Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual machine) files, allowing attackers to gain privileges via a Trojan horse Centreon-autodisco executable file that is launched by cron.
References
Configurations
Information
Published : 2019-11-21 10:15
Updated : 2020-03-06 12:15
NVD link : CVE-2019-16406
Mitre link : CVE-2019-16406
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
centreon
- centreon_web