Skip to main content
security bulletin

CVE-2024-46924/CVE-2025-3767 - Centreon BAM - High severity

  • March 10, 2025
  • 1 reply
  • 408 views

lpinsivy
Centreonian
Forum|alt.badge.img+21

Publication date: March 10th, 2025

Component: centreon-bam-server (on central server)

Feature: Boolean KPI listing

 

Description: SQLi in the listing of Boolean KPI, only accessible to authenticated users with high privilege access.

 

ReferenceCVE-2025-3767 (previously CVE-2024-46924)

CVSS7.2 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 

SeverityHIGH

 

Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Central server:

These versions include cumulative fixes from prior updates.

 

Reporter: Matthew Taylor, Ludovic Tavernier and Remi Millerand from Algosecure

Submission: August 30, 2024
 

Stay ahead of potential threats by subscribing to the Security Bulletin section. You’ll receive instant notifications whenever a new bulletin is published, ensuring your infrastructure remains secure and up to date.

1 reply

lpinsivy
Centreonian
Forum|alt.badge.img+21
  • Author
  • Centreonian
  • April 22, 2025

The CVE ID CVE-2024-46924 has been moved to CVE-2025-3767