Vulnerability record · CVE-2022-41142 · published 26 January 2023
CVE-2022-41142: Centreon poller resource configuration SQL injection privilege escalation
Centreon · Centreon
Centreon fails to validate a user-supplied string when handling requests to configure poller resources, allowing that string to be used directly in SQL queries. An authenticated attacker can exploit this SQL injection to escalate privileges to administrator level. The flaw is remotely reachable and requires only low-privileged credentials.
Description
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to configure poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18304.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and a very high EPSS score, but exploitation requires valid low-privileged credentials and no KEV listing or public exploit is confirmed.
What it is
Centreon fails to validate a user-supplied string when handling requests to configure poller resources, allowing that string to be used directly in SQL queries. An authenticated attacker can exploit this SQL injection to escalate privileges to administrator level. The flaw is remotely reachable and requires only low-privileged credentials.
Impact
An attacker with a low-privileged account gains administrator-level control of the Centreon installation, including full read and write access to its data. This can lead to compromise of monitoring configuration and any systems Centreon manages.
Attack surface
Reached over the network via requests to configure poller resources; the CVSS vector shows AV:N/AC:L/PR:L/UI:N, so authentication with low privileges is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.850 (99.7th percentile), indicating strong likelihood of exploitation activity; references are only vendor and ZDI advisories with no public exploit tag.
What to do
- Apply the Centreon fix for CVE-2022-41142 as soon as a patched release is available; the record does not name affected or fixed versions, so confirm with the vendor advisory.
- Restrict network access to the Centreon web interface to trusted management networks.
- Review and reduce accounts holding poller resource configuration permissions, applying least privilege.
- Audit existing Centreon accounts for unexpected administrator-level privileges and remove any that are not justified.
Detection
- Monitor Centreon web logs for requests to poller resource configuration endpoints containing SQL metacharacters or unusual query strings.
- Alert on creation or modification of administrator accounts, especially from sessions tied to low-privileged users.
- Baseline normal poller configuration activity and flag configuration changes outside expected maintenance windows.
- Correlate database error responses or anomalous SQL activity originating from the Centreon application.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/centreon/centreon/security/policy | Third Party Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-22-1326/ | Third Party AdvisoryVDB Entry |
| https://github.com/centreon/centreon/security/policy | Third Party Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-22-1326/ | Third Party AdvisoryVDB Entry |
Track CVE-2022-41142 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-41142), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.