CVE-2025-5965: RCE via the backup feature available only to user with high privilege
In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Backup configuration in the administration setup modules) allows OS Command Injection.This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5965?
CVE-2025-5965 has been rated as a high severity vulnerability due to its potential for OS command injection.
How do I fix CVE-2025-5965?
To remediate CVE-2025-5965, ensure you update Centreon Infra Monitoring to a version that is not affected, specifically after 25.10.2 or 24.10.15.
What impact does CVE-2025-5965 have?
CVE-2025-5965 can allow a user with high privileges to execute arbitrary commands on the server, compromising system integrity.
Which versions of Centreon Infra Monitoring are affected by CVE-2025-5965?
CVE-2025-5965 affects Centreon Infra Monitoring versions from 24.04.0 to 24.04.19, 24.10.0 to 24.10.15, and 25.10.0 to 25.10.2.
Who is impacted by CVE-2025-5965?
Organizations using vulnerable versions of Centreon Infra Monitoring with high privilege users are at risk due to CVE-2025-5965.