Vulnerability record · CVE-2022-42429 · published 29 March 2023
CVE-2022-42429: Centreon poller broker config SQL injection privilege escalation
Centreon · Centreon
Centreon fails to validate a user-supplied string before using it to build SQL queries when handling requests that modify poller broker configuration. An authenticated remote attacker can inject SQL through that path and escalate their privileges to administrator. The flaw is a classic CWE-89 SQL injection in a monitoring platform, which makes it a serious post-authentication escalation risk.
Description
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18557.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high confidentiality, integrity and availability impact and a very high EPSS score, though exploitation requires an authenticated account and no KEV listing exists.
What it is
Centreon fails to validate a user-supplied string before using it to build SQL queries when handling requests that modify poller broker configuration. An authenticated remote attacker can inject SQL through that path and escalate their privileges to administrator. The flaw is a classic CWE-89 SQL injection in a monitoring platform, which makes it a serious post-authentication escalation risk.
Impact
An attacker with a low-privileged account gains full administrative control of the Centreon installation, including the ability to read and modify monitoring data and configuration. That level of access can be used to pivot into monitored infrastructure or disrupt monitoring.
Attack surface
Reached over the network through the Centreon web interface by sending crafted requests to the poller broker configuration endpoint. Authentication is required (CVSS PR:L) and no user interaction is needed (UI:N).
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is very high at 0.76134 (99.5th percentile), indicating strong predicted exploitation activity, but the references are only vendor and advisory entries with no public exploit tag.
What to do
- Apply the Centreon patch that fixes the poller broker configuration SQL injection; this is the primary action.
- If patching is delayed, restrict access to the Centreon web interface to trusted management networks and remove or disable unused low-privileged accounts.
- Enforce least privilege on Centreon accounts so that only administrators can modify poller broker configuration.
- Monitor and alert on privilege changes and configuration modifications made by non-administrative accounts.
- Review Centreon logs for anomalous SQL-related errors or unexpected poller broker configuration changes.
Detection
- Search Centreon web and application logs for requests to poller broker configuration endpoints containing SQL metacharacters or unexpected query fragments.
- Alert on privilege escalation events, such as a non-admin account gaining administrator rights or performing admin-only actions.
- Baseline normal poller broker configuration changes and alert on modifications outside change windows or from unusual source IPs.
- Correlate Centreon authentication events with subsequent configuration changes to spot low-privileged accounts performing administrative operations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-22-1394/ | Third Party AdvisoryVDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-22-1394/ | Third Party AdvisoryVDB Entry |
Track CVE-2022-42429 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-42429), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.