CVE-2025-8432: CentreonBI user account on the MBI server can execute commands as root by modifying script runned by the CRON
Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8432?
CVE-2025-8432 has a severity level that indicates a significant security risk due to incorrect default permissions allowing unauthorized script embedding.
How do I fix CVE-2025-8432?
To fix CVE-2025-8432, upgrade Centreon Infra Monitoring to version 24.10.6, 24.04.9, or 23.10.15 or later.
What versions are affected by CVE-2025-8432?
CVE-2025-8432 affects Centreon Infra Monitoring versions prior to 24.10.6, 24.04.9, and 23.10.15.
Who is impacted by CVE-2025-8432?
CVE-2025-8432 impacts systems using specific versions of Centreon Infra Monitoring that allow embedding scripts through the CentreonBI user account.
Can CVE-2025-8432 lead to data breaches?
Yes, CVE-2025-8432 can potentially lead to data breaches as it allows unauthorized users to execute scripts on the server.