Vulnerability record · CVE-2022-42425 · published 29 March 2023
CVE-2022-42425: Centreon poller broker config SQL injection privilege escalation
Centreon · Centreon
Centreon fails to validate a user-supplied string before using it to build SQL queries when handling requests that modify poller broker configuration. An authenticated attacker can inject SQL through this path and escalate their privileges to administrator level. The flaw is a classic CWE-89 SQL injection in a remote, network-reachable component.
Description
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18555.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with full confidentiality, integrity and availability impact plus a very high EPSS score, though exploitation requires an authenticated account.
What it is
Centreon fails to validate a user-supplied string before using it to build SQL queries when handling requests that modify poller broker configuration. An authenticated attacker can inject SQL through this path and escalate their privileges to administrator level. The flaw is a classic CWE-89 SQL injection in a remote, network-reachable component.
Impact
An attacker with a low-privileged account gains full administrative control of the Centreon installation, including the ability to alter monitoring configuration and potentially pivot to managed hosts.
Attack surface
Reached over the network via requests that modify poller broker configuration; the CVSS vector (AV:N/PR:L/UI:N) indicates authentication is required but no user interaction is needed.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged beyond the ZDI advisory, but EPSS is very high at 0.761 (99.5th percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Apply the vendor patch for the affected Centreon release as the first action.
- Restrict network access to Centreon web interfaces to trusted management networks.
- Audit and minimize accounts with privileges to modify poller broker configuration.
- Enforce least privilege and strong authentication for all Centreon users.
- Monitor for unexpected changes to poller broker settings.
Detection
- Review web and application logs for requests to poller broker configuration endpoints containing SQL metacharacters.
- Alert on privilege changes or new administrator accounts in Centreon.
- Baseline and monitor poller broker configuration for unauthorized modifications.
- Correlate Centreon access logs with database query anomalies where logging is available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-22-1396/ | Third Party AdvisoryVDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-22-1396/ | Third Party AdvisoryVDB Entry |
Track CVE-2022-42425 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-42425), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.