Description
Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15.
Published: 2025-10-27
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Oct 2025 14:00:00 +0000


Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Centreon
Centreon centreon
Vendors & Products Centreon
Centreon centreon

Mon, 27 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 10:15:00 +0000

Type Values Removed Values Added
Description Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15.
Title CentreonBI user account on the MBI server can execute commands as root by modifying script runned by the CRON
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Centreon Centreon
cve-icon MITRE

Status: PUBLISHED

Assigner: Centreon

Published:

Updated: 2025-10-30T13:51:12.045Z

Reserved: 2025-07-31T18:48:13.937Z

Link: CVE-2025-8432

cve-icon Vulnrichment

Updated: 2025-10-27T15:10:28.331Z

cve-icon NVD

Status : Deferred

Published: 2025-10-27T10:15:39.350

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-8432

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-27T22:03:56Z

Weaknesses