First published: Thu Jan 16 2020(Updated: )
Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges. (cwrapper_perl is a setuid executable allowing execution of Perl scripts with root privileges.)
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Centreon Centreon | <=19.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20327 is a vulnerability in Centreon Infrastructure Monitoring Software that allows local attackers to gain privileges.
The severity of CVE-2019-20327 is high with a CVSS score of 7.8.
CVE-2019-20327 is caused by insecure permissions in the cwrapper_perl component of Centreon Infrastructure Monitoring Software, allowing local attackers to execute Perl scripts with root privileges.
To fix CVE-2019-20327, it is recommended to update Centreon Infrastructure Monitoring Software to version 19.11 or later, which resolves the insecure permissions issue.
You can find more information about CVE-2019-20327 on the Centreon website at https://www.centreon.com/en/.