CVE-2019-19699 is an authenticated remote code execution vulnerability in Centreon Infrastructure Monitoring Software through version 19.10. The vulnerability arises from a misconfiguration in the handling of Pollers and the apache crontab. An attacker with administrative access to the Centreon Web Interface can create a custom command and set it as the Pollers Post-Restart Command. This command is then executed by the apache user, who has write access to an executable file that is run as root by a daily cron job. This allows the attacker to inject arbitrary code that will be executed with root privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module: 'centreon_pollers_auth_rce.rb', which targets Centreon monitoring software running on Linux. The exploit leverages authenticated access to the Centreon web panel, specifically requiring administrative credentials with rights to manage pollers. By abusing the poller management functionality, the module allows an attacker to execute arbitrary commands on the target system. The module supports both reverse shell (bash) and Meterpreter payloads, providing the attacker with a remote shell or advanced session on the compromised host. The attack is performed over HTTP(S) and requires knowledge of the Centreon web panel's URI, as well as valid credentials. The code references several file paths relevant to Centreon's configuration and operation, which are used in the exploitation process. The exploit is weaponized, as it is part of the Metasploit framework and supports customizable payloads. The repository is structured as a single Ruby file, following Metasploit's module conventions, and is intended for use within the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.