CVE-2025-5965
7.2Centreon · Infra Monitoring
Centreon Infra Monitoring is vulnerable to OS Command Injection via the backup configuration module, allowing high privileged users to execute arbitrary commands.
Executive summary
An OS Command Injection vulnerability in Centreon Infra Monitoring allows authenticated administrators to execute arbitrary system commands, posing a critical risk to server integrity.
Vulnerability
The application fails to properly neutralize special elements within the backup configuration parameters. This allows an authenticated user with high privileges to perform OS Command Injection by concatenating malicious instructions to the backup setup.
Business impact
The ability to execute arbitrary OS commands on the monitoring infrastructure facilitates full system compromise. Given the CVSS score of 7.2, this vulnerability represents a high risk to business operations, as an attacker could pivot into the internal network, exfiltrate sensitive monitoring data, or disrupt critical infrastructure services.
Remediation
Immediate Action: Update Centreon Infra Monitoring to version 25.10.2, 24.10.15, or 24.04.19 respectively, as specified in the official vendor security bulletin.
Proactive Monitoring: Review administrative access logs for suspicious input patterns or unusual process execution related to the backup configuration module.
Compensating Controls: Restrict access to the administration setup modules to only the most essential personnel and ensure that the application runs with the minimum required system privileges to limit the potential impact of command execution.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
This vulnerability presents a significant security risk due to the potential for complete system takeover. Administrators should prioritize patching the affected Centreon instances immediately to prevent exploitation. If immediate patching is not feasible, restrict administrative access to the backup configuration interface until the updates can be applied.
More Centreon CVEs
Sources
Originally found and disclosed by h00die-gr3y, per the CVE Program record.