CVE-2019-16405
Summary
| CVE | CVE-2019-16405 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-21 18:15:00 UTC |
| Updated | 2022-03-31 18:23:00 UTC |
| Description | Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings. CVE-2019-16405 and CVE-2019-17501 are similar to one another and may be the same. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Centreon | Centreon Web | All | All | All | All |
| Application | Centreon | Centreon Web | 19.04.4 | All | All | All |
| Application | Centreon | Centreon Web | 19.04.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Page Not Found | MISC | thecybergeek.co.uk | Broken Link |
| Page Not Found | MISC | thecybergeek.co.uk | Exploit, Third Party Advisory |
| Centreon Web 2.8.32 — Centreon 19.10 documentation | CONFIRM | documentation.centreon.com | |
| Centreon 19.04 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| fix(security): remove command test execution - CVE 2019-16405 by lpinsivy · Pull Request #7864 · centreon/centreon · GitHub | CONFIRM | github.com | |
| Centreon Web 19.10.17 — Centreon 19.10 documentation | CONFIRM | documentation.centreon.com | |
| Centreon Web 19.04.18 — Centreon 19.10 documentation | CONFIRM | documentation.centreon.com | |
| GitHub - TheCyberGeek/CVE-2019-16405.rb: Metasploit module & Python script for CVE-2019-16405 | MISC | github.com | Patch |
| fix(security): remove command test execution for 2.8.x - CVE 2019-16405 by lpinsivy · Pull Request #7884 · centreon/centreon · GitHub | CONFIRM | github.com | |
| Centreon Web 18.10.12 — Centreon 19.10 documentation | CONFIRM | documentation.centreon.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.