CVE-2019-16405
Last modified
CVE-2019-16405 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings. CVE-2019-16405 and CVE-2019-17501 are similar to one another and may be the same.. EPSS estimates a 27.00% chance of exploitation in the next 30 days.
Description
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings. CVE-2019-16405 and CVE-2019-17501 are similar to one another and may be the same.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Centreon | Centreon Web | < 2.8.30 |
| Centreon | Centreon Web | >= 18.10.0, < 18.10.8 |
| Centreon | Centreon Web | >= 19.04.0, < 19.04.5 |
| Centreon | Centreon Web | >= 19.10.0, < 19.10.2 |
References
- http://packetstormsecurity.com/files/155999/Centreon-19.04-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10.htmlRelease Notes, Vendor Advisory
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.04.htmlRelease Notes, Vendor Advisory
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.10.htmlRelease Notes, Vendor Advisory
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8.htmlRelease Notes, Vendor Advisory
- https://github.com/TheCyberGeek/CVE-2019-16405.rbPatch, Third Party Advisory
- https://github.com/centreon/centreon/pull/7864Issue Tracking, Patch, Third Party Advisory
- https://github.com/centreon/centreon/pull/7884Issue Tracking, Patch, Third Party Advisory
- https://thecybergeek.co.uk/cves/2019/09/19/CVEs.htmlExploit, Third Party Advisory
- http://packetstormsecurity.com/files/155999/Centreon-19.04-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10.htmlRelease Notes, Vendor Advisory
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.04.htmlRelease Notes, Vendor Advisory
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.10.htmlRelease Notes, Vendor Advisory
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8.htmlRelease Notes, Vendor Advisory
- https://github.com/TheCyberGeek/CVE-2019-16405.rbPatch, Third Party Advisory
- https://github.com/centreon/centreon/pull/7864Issue Tracking, Patch, Third Party Advisory
- https://github.com/centreon/centreon/pull/7884Issue Tracking, Patch, Third Party Advisory
- https://thecybergeek.co.uk/cves/2019/09/19/CVEs.htmlExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-16405?
How severe is CVE-2019-16405?
How do I fix CVE-2019-16405?
Are you affected by CVE-2019-16405?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
