RULE(RULE ID:330388)

Rule General Information
Release Date: 2020-06-11
Rule Name: Centreon server_ip field OS Command Injection Vulnerability (CVE-2020-9463)
Severity:
CVE ID:
Rule Protection Details
Description: Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an api/internal.php?object=centreon_configuration_remote request.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://code610.blogspot.com/2020/02/postauth-rce-in-centreon-1910.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.centreon.com/