Vulnerabilidades em Centreon

52 resultados
Análise Vexday

Com 51 CVEs catalogadas e nenhuma confirmada em exploração ativa no catálogo CISA KEV, o Centreon apresenta taxa de exploração abaixo da média geral do catálogo. Ainda assim, o cenário exige atenção: a CVE mais crítica em destaque, CVE-2022-41142, registra EPSS de 0,8614 — valor elevado que indica alta probabilidade de exploração —, e há 4 vulnerabilidades de severidade crítica no total. O tipo de falha mais frequente é CWE-89 (SQL Injection), categoria historicamente associada a impactos severos em integridade e confidencialidade de dados, reforçando a necessidade de revisão cuidadosa das superfícies de entrada da plataforma. A existência de ao menos uma PoC pública disponível reduz a barreira técnica para potenciais atacantes, tornando a priorização de patches críticos uma medida urgente para equipes que operam esse ambiente.

CVE-2022-41142HIGHThis vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploEPSS 86.1%CVE-2022-42429HIGHThis vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploEPSS 77.6%CVE-2022-42424HIGHThis vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploEPSS 76.1%CVE-2022-42425HIGHThis vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploEPSS 76.1%CVE-2022-42427HIGHThis vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploEPSS 76.1%CVE-2024-0637HIGHCentreon updateDirectory SQL Injection Remote Code Execution VulnerabilityEPSS 72.3%CVE-2024-23115HIGHCentreon updateGroups SQL Injection Remote Code Execution VulnerabilityEPSS 67.5%CVE-2024-23118HIGHCentreon updateContactHostCommands SQL Injection Remote Code Execution VulnerabilityEPSS 53.4%CVE-2024-23116HIGHCentreon updateLCARelation SQL Injection Remote Code Execution VulnerabilityEPSS 53.4%CVE-2024-23117HIGHCentreon updateContactServiceCommands SQL Injection Remote Code Execution VulnerabilityEPSS 53.4%CVE-2024-5725HIGHCentreon initCurveList SQL Injection Remote Code Execution VulnerabilityEPSS 47.4%CVE-2024-5723HIGHCentreon updateServiceHost SQL Injection Remote Code Execution VulnerabilityEPSS 40.7%CVE-2025-5965HIGHRCE via the backup feature available only to user with high privilegeEPSS 24.8%CVE-2025-5946HIGHRCE via the poller reload feature available only to user with high privilegeEPSS 13.8%CVE-2025-15029CRITICALAn unauthenticated user is able to introduce SQL Injection using the Awie export moduleEPSS 11.2%CVE-2012-5967SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authenticated usersEPSS 3.3%CVE-2022-42428HIGHThis vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploEPSS 2.9%CVE-2022-42426HIGHThis vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploEPSS 2.9%CVE-2022-34871HIGHThis vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploEPSS 2.7%CVE-2022-34872MEDIUMThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Authentication is requirEPSS 2.1%