CVE-2020-9463
Centreon vulnerability analysis and mitigation

Overview

Centreon 19.10 contains a remote code execution vulnerability (CVE-2020-9463) that allows authenticated users to execute arbitrary OS commands. The vulnerability exists in the server_ip field within JSON data sent to the api/internal.php endpoint with the object=centreon_configuration_remote parameter (MITRE CVE).

Technical details

The vulnerability involves shell metacharacter injection through the server_ip field in JSON data sent to the api/internal.php endpoint. The affected endpoint is specifically api/internal.php?object=centreon_configuration_remote. The vulnerability has a CVSS v3.1 Base Score of 8.8 (High) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating network accessibility, low attack complexity, and high impact across confidentiality, integrity, and availability (AttackerKB).

Impact

The vulnerability can lead to complete system compromise, allowing attackers to execute arbitrary operating system commands on the affected Centreon server. Given Centreon's role as a centralized IT management solution, successful exploitation could provide attackers with access to network device information and potential pivot points across the corporate network (AttackerKB).

Community reactions

According to security researchers, Centreon has a relatively small internet-exposed footprint with approximately 40 internet-facing applications identified through Shodan searches. The official GitHub repository shows limited community engagement with only a few hundred stars and forks (AttackerKB).

Additional resources


SourceThis report was generated using AI

Related Centreon vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-3872HIGH7.2
  • CentreonCentreon
  • cpe:2.3:a:centreon:centreon
NoYesApr 24, 2025
CVE-2025-3767HIGH7.2
  • CentreonCentreon
  • cpe:2.3:a:centreon:centreon
NoYesApr 22, 2025
CVE-2024-45756HIGH7.2
  • CentreonCentreon
  • cpe:2.3:a:centreon:centreon
NoYesNov 25, 2024
CVE-2024-45755HIGH7.2
  • CentreonCentreon
  • cpe:2.3:a:centreon:centreon
NoYesNov 25, 2024
CVE-2024-45754HIGH7.2
  • CentreonCentreon
  • cpe:2.3:a:centreon:centreon
NoYesOct 11, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management