PT-2018-10686 · Centreon · Centreon+1
Published
2018-06-25
·
Updated
2022-05-14
·
CVE-2018-11587
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Centreon version 3.4.6
Centreon Web version 2.8.23
Description
The issue concerns Remote Code Execution via the RPN value in the Virtual Metric form. This is specifically related to the centreonGraph.class.php file.
Recommendations
For Centreon version 3.4.6, update to a version that fixes this issue.
For Centreon Web version 2.8.23, update to a version that fixes this issue.
As a temporary workaround, consider restricting access to the Virtual Metric form in centreonGraph.class.php to minimize the risk of exploitation.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centreon
Centreon Web