Centreon Authentication Mechanism Security Bypass Vulnerability

BID:37383

Info

Centreon Authentication Mechanism Security Bypass Vulnerability

Bugtraq ID: 37383
Class: Design Error
CVE: CVE-2009-4368
Remote: Yes
Local: No
Published: Dec 17 2009 12:00AM
Updated: Apr 13 2015 09:05PM
Credit: Julien Cayssol
Vulnerable: Centreon Centreon 2.1.3
Centreon Centreon 2.1.2
Centreon Centreon 2.1.1
Centreon Centreon 2.0.2
Centreon Centreon 2.0.1
Centreon Centreon 2.0.RC5
Centreon Centreon 2.0.RC4
Centreon Centreon 2.0.RC3
Centreon Centreon 2.0.RC2
Centreon Centreon 2.0.RC1
Centreon Centreon 2.0
Not Vulnerable: Centreon Centreon 2.1.4

Discussion

Centreon Authentication Mechanism Security Bypass Vulnerability

Centreon is prone to a security-bypass vulnerability.

An attacker can exploit this issue to bypass certain security restrictions and gain unauthorized access to certain functionality, which may lead to further attacks.

Versions prior to Centreon 2.1.4 are vulnerable.

Exploit / POC

Centreon Authentication Mechanism Security Bypass Vulnerability

An attacker can exploit this issue through a browser.

Solution / Fix

Centreon Authentication Mechanism Security Bypass Vulnerability

Solution:
Updates are available. Please see the references for details.

References

Centreon Authentication Mechanism Security Bypass Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report