CVE-2025-15029

9.8

Centreon · Infra Monitoring

An SQL injection vulnerability in the Centreon Infra Monitoring Awie export modules allows unauthenticated attackers to execute arbitrary SQL commands.

Executive summary

An unauthenticated SQL injection vulnerability in Centreon Infra Monitoring poses a critical risk of full database compromise and unauthorized data access.

Vulnerability

This vulnerability is an SQL injection (CWE-89) located within the Awie export modules, which fails to properly neutralize special elements in SQL commands, allowing unauthenticated remote attackers to interact directly with the backend database.

Business impact

The vulnerability carries a CVSS score of 9.8, reflecting its critical severity and the ease with which it can be exploited by remote, unauthenticated actors. Successful exploitation grants attackers the ability to read, modify, or delete sensitive monitoring data, potentially leading to a total loss of confidentiality, integrity, and availability of the affected system.

Remediation

Immediate Action: Update Centreon Infra Monitoring to the latest patched versions (25.10.2, 24.10.3, or 24.04.3) as specified in the official vendor security bulletin.

Proactive Monitoring: Review web server and database access logs for suspicious query patterns, such as unexpected SQL syntax or unauthorized access attempts targeting the Awie export modules.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection payloads targeting the application endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Centreon Infra Monitoring must prioritize applying the provided patches immediately. Because this vulnerability allows for unauthenticated remote code execution or full database manipulation, failure to patch leaves the internal monitoring infrastructure exposed to trivial exploitation by external attackers.

More Centreon CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Analyst report written
  4. Fix documented version 25.10.2 per CVE record

Sources

Originally found and disclosed by marceloQJ, per the CVE Program record.