SQL Injection Vulnerability in Centreon's Web Interface
CVE-2024-55573
What is CVE-2024-55573?
CVE-2024-55573 is a critical SQL injection vulnerability identified in the Centreon web interface, specifically affecting versions prior to 24.10.3, 24.04.9, 23.10.19, and 23.04.24. Centreon is widely utilized for monitoring IT and network infrastructures, providing organizations with insights into performance and availability. This vulnerability arises when users with high privileges can inject malicious SQL code through the form designed for creating virtual metrics. If exploited, it could lead to unauthorized access to sensitive data and potentially compromise the integrity of the system.
Technical Details
The flaw in CVE-2024-55573 permits users with elevated permissions to manipulate SQL queries executed by the Centreon web interface. This results from insufficient input validation, allowing for the injection of arbitrary SQL code during the creation of virtual metrics. As a consequence, attackers could retrieve, modify, or delete records in the database, depending on their permissions and the nature of the exploitation.
Potential Impact of CVE-2024-55573
-
Data Breaches: The vulnerability can enable attackers to access sensitive information stored in the database, leading to significant privacy violations and potential regulatory repercussions.
-
System Compromise: Exploiting this vulnerability could allow attackers to escalate their privileges or execute additional malicious commands within the Centreon environment, jeopardizing the overall network security.
-
Operational Disruption: Successful exploitation may lead to the manipulation or deletion of critical monitoring metrics, impairing an organization’s ability to effectively monitor and respond to infrastructure issues, potentially resulting in downtime or degraded service levels.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
