Vulnerability record · CVE-2024-23116 · published 1 April 2024
CVE-2024-23116: Centreon updateLCARelation SQL injection leads to remote code execution
Centreon · Centreon Web
CVE-2024-23116 is a SQL injection in the updateLCARelation function of Centreon, caused by a user-supplied string being used to build SQL queries without proper validation. It is described as a remote code execution vulnerability, meaning successful exploitation can go beyond data access to code execution on the affected installation. Authentication is required, which limits the attacker pool but not the severity for exposed, internet-facing deployments.
Description
Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateLCARelation function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-22296.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 with network reachability and code execution impact, plus a very high EPSS score, outweigh the authentication requirement.
What it is
CVE-2024-23116 is a SQL injection in the updateLCARelation function of Centreon, caused by a user-supplied string being used to build SQL queries without proper validation. It is described as a remote code execution vulnerability, meaning successful exploitation can go beyond data access to code execution on the affected installation. Authentication is required, which limits the attacker pool but not the severity for exposed, internet-facing deployments.
Impact
An authenticated attacker can execute arbitrary code in the context of the service account, gaining control over the Centreon application and its data. This can lead to full compromise of the monitoring platform and any credentials or systems it manages.
Attack surface
The flaw is reached remotely over the network through the Centreon web interface, per the CVSS vector AV:N. Exploitation requires authentication with high privileges (PR:H) and no user interaction (UI:N).
Exploitation
The record does not list this CVE in CISA KEV and documents no ransomware use. EPSS is high at roughly 0.53 probability (99th percentile), and the only references are the ZDI advisory tagged Patch and Third Party Advisory, so no public exploit code is confirmed by the supplied data.
What to do
- Apply the vendor patch referenced in the ZDI advisory (ZDI-24-116) as the first action.
- Restrict network access to the Centreon web interface and avoid exposing it directly to the internet.
- Enforce least privilege and review which accounts hold the high privileges required to reach updateLCARelation.
- Monitor and audit administrative accounts for unexpected activity, since exploitation requires authenticated access.
- Validate and sanitize user-supplied input in updateLCARelation and similar SQL-building functions if custom code is involved.
Detection
- Review Centreon web and database logs for anomalous SQL queries or errors originating from the updateLCARelation function.
- Alert on unexpected child processes or command execution spawned by the Centreon service account.
- Monitor for unusual authenticated sessions, especially from new or unexpected source IPs, against the Centreon web interface.
- Correlate database query patterns with requests to the updateLCARelation endpoint to spot injection attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-24-116/ | PatchThird Party Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-24-116/ | PatchThird Party Advisory |
Track CVE-2024-23116 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-23116), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.