CVE-2025-5965

7.2

Centreon · Infra Monitoring

Centreon Infra Monitoring is vulnerable to OS Command Injection via the backup configuration module, allowing high privileged users to execute arbitrary commands.

Executive summary

An OS Command Injection vulnerability in Centreon Infra Monitoring allows authenticated administrators to execute arbitrary system commands, posing a critical risk to server integrity.

Vulnerability

The application fails to properly neutralize special elements within the backup configuration parameters. This allows an authenticated user with high privileges to perform OS Command Injection by concatenating malicious instructions to the backup setup.

Business impact

The ability to execute arbitrary OS commands on the monitoring infrastructure facilitates full system compromise. Given the CVSS score of 7.2, this vulnerability represents a high risk to business operations, as an attacker could pivot into the internal network, exfiltrate sensitive monitoring data, or disrupt critical infrastructure services.

Remediation

Immediate Action: Update Centreon Infra Monitoring to version 25.10.2, 24.10.15, or 24.04.19 respectively, as specified in the official vendor security bulletin.

Proactive Monitoring: Review administrative access logs for suspicious input patterns or unusual process execution related to the backup configuration module.

Compensating Controls: Restrict access to the administration setup modules to only the most essential personnel and ensure that the application runs with the minimum required system privileges to limit the potential impact of command execution.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

This vulnerability presents a significant security risk due to the potential for complete system takeover. Administrators should prioritize patching the affected Centreon instances immediately to prevent exploitation. If immediate patching is not feasible, restrict administrative access to the backup configuration interface until the updates can be applied.

More Centreon CVEs

Sources

Originally found and disclosed by h00die-gr3y, per the CVE Program record.