Centreon Infra Monitoring Incorrect Default Permissions Vulnerability Allowing Script Embedding

Vulnerability

A vulnerability exists in Centreon Infra Monitoring versions 24.10.0 prior to 24.10.6, 24.04.0 prior to 24.04.9, and 23.10.0 prior to 23.10.15. This vulnerability, caused by incorrect default permissions in the Centreon MBI modules, allows users to embed scripts within other scripts on the MBI server.

Impact

Exploitation of this vulnerability could lead to unauthorized script execution, potentially allowing for further attacks or system compromise.

Remediation

Users can upgrade to Centreon versions 24.10.13, 24.10.9, 25.09.1, or 23.10.15 to address this vulnerability.

Added: Oct 27, 2025, 10:17 AM
Updated: Oct 27, 2025, 1:49 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.