Incorrect Default Permissions in Centreon Infra Monitoring Affects Multiple Versions
CVE-2025-8432

8.4HIGH

Key Information:

Vendor

Centreon

Vendor
CVE Published:
27 October 2025

What is CVE-2025-8432?

The Centreon Infra Monitoring software faces a significant security issue due to incorrect default permissions in its MBI modules. This vulnerability allows users with a CentreonBI account to embed scripts within scripts on the MBI server, potentially leading to unauthorized access and manipulation of sensitive data. Versions affected include 24.10.0 to 24.10.5, 24.04.0 to 24.04.8, and 23.10.0 to 23.10.14. It is crucial for users to apply the necessary updates to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Infra Monitoring 24.10.0 < 24.10.6

Infra Monitoring 24.04.0 < 24.04.9

Infra Monitoring 23.10.0 < 23.10.15

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stago
.