Weak Permission Issues in Centreon Web Affecting VMware and VirtualBox Users
CVE-2019-16406
7.8HIGH
What is CVE-2019-16406?
Centreon Web versions, including 19.04.4, have been found to exhibit weak permission settings within their OVA and OVF files used for VMware and VirtualBox deployments. This vulnerability allows potential attackers to exploit these weak permissions to execute a Trojan horse executable linked to Centreon's auto-discovery feature. The executable can be invoked through scheduled cron jobs, leading to unauthorized privilege escalation and compromising the system security.
