CVE-2011-4432: Medium severity centreon vulnerability
www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to determine cleartext passwords via a rainbow-table approach.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4432?
CVE-2011-4432 has a medium severity level due to its potential for exposing user passwords through rainbow table attacks.
How do I fix CVE-2011-4432?
To fix CVE-2011-4432, upgrade to Centreon version 2.3.2 or later, which implements proper password hashing with salt.
What software is affected by CVE-2011-4432?
CVE-2011-4432 affects various versions of Centreon prior to 2.3.2, including all 1.4.x and 2.0.x versions.
What kind of attack does CVE-2011-4432 enable?
CVE-2011-4432 enables attackers to use rainbow tables to efficiently crack passwords due to the lack of salt in the password hashing process.
Is CVE-2011-4432 still a concern today?
While CVE-2011-4432 is an older vulnerability, it remains a concern for systems that have not been updated and still run affected versions of Centreon.