CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
85.3%
Centreon Web 19.04.4 allows Remote Code Execution by an administrator who can modify Macro Expression location settings.
packetstormsecurity.com/files/155999/Centreon-19.04-Remote-Code-Execution.html
documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10.html
documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.04.html
documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.10.html
documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8.html
github.com/advisories/GHSA-4f26-v6fr-9hmp
github.com/centreon/centreon/pull/7864
github.com/centreon/centreon/pull/7884
github.com/centreon/centreon/releases/tag/19.04.5
github.com/TheCyberGeek/CVE-2019-16405.rb
nvd.nist.gov/vuln/detail/CVE-2019-16405
thecybergeek.co.uk/cves/2019/09/17/CVE-2019-16405-06.html
thecybergeek.co.uk/cves/2019/09/19/CVEs.html
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
85.3%