CVE-2025-8432

Source
https://cve.org/CVERecord?id=CVE-2025-8432
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8432.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-8432
Published
2025-10-27T10:08:33.662Z
Modified
2026-04-10T05:36:16.868532Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
CentreonBI user account on the MBI server can execute commands as root by modifying script runned by the CRON
Details

Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15.

Database specific
{
    "cwe_ids": [
        "CWE-276"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8432.json",
    "cna_assigner": "Centreon"
}
References

Affected packages

Git / github.com/centreon/centreon

Affected ranges

Type
GIT
Repo
https://github.com/centreon/centreon
Events
Database specific
{
    "versions": [
        {
            "introduced": "24.10.0"
        },
        {
            "fixed": "24.10.6"
        }
    ]
}
Type
GIT
Repo
https://github.com/centreon/centreon
Events
Database specific
{
    "versions": [
        {
            "introduced": "24.04.0"
        },
        {
            "fixed": "24.04.9"
        }
    ]
}
Type
GIT
Repo
https://github.com/centreon/centreon
Events
Database specific
{
    "versions": [
        {
            "introduced": "23.10.0"
        },
        {
            "fixed": "23.10.15"
        }
    ]
}

Affected versions

centreon-awie-23.*
centreon-awie-23.10.0
centreon-awie-24.*
centreon-awie-24.04.0
centreon-awie-24.10.0
centreon-awie-24.10.1
centreon-dsm-23.*
centreon-dsm-23.10.0
centreon-dsm-24.*
centreon-dsm-24.04.0
centreon-dsm-24.04.2
centreon-dsm-24.04.3
centreon-dsm-24.10.0
centreon-dsm-24.10.1
centreon-gorgone-23.*
centreon-gorgone-23.10.0
centreon-gorgone-23.10.1
centreon-gorgone-23.10.2
centreon-gorgone-23.10.3
centreon-gorgone-23.10.5
centreon-gorgone-23.10.6
centreon-gorgone-23.10.7
centreon-gorgone-23.10.8
centreon-gorgone-23.10.9
centreon-gorgone-24.*
centreon-gorgone-24.04.0
centreon-gorgone-24.04.1
centreon-gorgone-24.04.2
centreon-ha-23.*
centreon-ha-23.10.0
centreon-ha-24.*
centreon-ha-24.04.0
centreon-open-tickets-23.*
centreon-open-tickets-23.10.0
centreon-open-tickets-24.*
centreon-open-tickets-24.04.0
centreon-open-tickets-24.04.1
centreon-open-tickets-24.04.2
centreon-open-tickets-24.04.3
centreon-open-tickets-24.10.0
centreon-open-tickets-24.10.1
centreon-open-tickets-24.10.2
centreon-web-23.*
centreon-web-23.10.0
centreon-web-23.10.1
centreon-web-23.10.11
centreon-web-23.10.12
centreon-web-23.10.13
centreon-web-23.10.14
centreon-web-23.10.2
centreon-web-23.10.3
centreon-web-23.10.4
centreon-web-23.10.5
centreon-web-23.10.6
centreon-web-23.10.7
centreon-web-23.10.8
centreon-web-23.10.9
centreon-web-24.*
centreon-web-24.04.0
centreon-web-24.04.2
centreon-web-24.04.3
centreon-web-24.04.4
centreon-web-24.04.5
centreon-web-24.04.6
centreon-web-24.04.7
centreon-web-24.04.8
centreon-web-24.10.0
centreon-web-24.10.1
centreon-web-24.10.2
centreon-web-24.10.3
centreon-web-24.10.4
centreon-web-24.10.5
centreon-widget-engine-status-23.*
centreon-widget-engine-status-23.10.0
centreon-widget-global-health-23.*
centreon-widget-global-health-23.10.0
centreon-widget-graph-monitoring-23.*
centreon-widget-graph-monitoring-23.10.0
centreon-widget-host-monitoring-23.*
centreon-widget-host-monitoring-23.10.0
centreon-widget-hostgroup-monitoring-23.*
centreon-widget-hostgroup-monitoring-23.10.0
centreon-widget-httploader-23.*
centreon-widget-httploader-23.10.0
centreon-widget-live-top10-cpu-usage-23.*
centreon-widget-live-top10-cpu-usage-23.10.0
centreon-widget-live-top10-memory-usage-23.*
centreon-widget-live-top10-memory-usage-23.10.0
centreon-widget-ntopng-listing-23.*
centreon-widget-ntopng-listing-23.10.0
centreon-widget-service-monitoring-23.*
centreon-widget-service-monitoring-23.10.0
centreon-widget-servicegroup-monitoring-23.*
centreon-widget-servicegroup-monitoring-23.10.0
centreon-widget-single-metric-23.*
centreon-widget-single-metric-23.10.0
centreon-widget-tactical-overview-23.*
centreon-widget-tactical-overview-23.10.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8432.json"