Weak Permission Issues in Centreon Web Affecting VMware and VirtualBox Users
CVE-2019-16406

7.8HIGH

Key Information:

Vendor

Centreon

Vendor
CVE Published:
21 November 2019

What is CVE-2019-16406?

Centreon Web versions, including 19.04.4, have been found to exhibit weak permission settings within their OVA and OVF files used for VMware and VirtualBox deployments. This vulnerability allows potential attackers to exploit these weak permissions to execute a Trojan horse executable linked to Centreon's auto-discovery feature. The executable can be invoked through scheduled cron jobs, leading to unauthorized privilege escalation and compromising the system security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.