« Volver al listado

CVE-2025-15026

Estado: AnalizadaCrítica (9.8)—

Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de autenticación faltante (CWE-306) en función crítica expuesta en red sin requerir credenciales (AV:N/PR:N/UI:N). Permite acceso no autorizado a funcionalidad de importación Awie con impacto de confidencialidad, integridad y disponibilidad críticos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-15026",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-15026",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-05T21:19:51.218301Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "bd4443e6-1eef-43f3-9886-25fc9ceeaae7",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "bd4443e6-1eef-43f3-9886-25fc9ceeaae7",
      "affectedData": [
        {
          "vendor": "Centreon",
          "modules": [
            "Awie import"
          ],
          "product": "Infra Monitoring",
          "versions": [
            {
              "status": "affected",
              "version": "25.10.0",
              "lessThan": "25.10.2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "24.10.0",
              "lessThan": "24.10.3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "24.04.0",
              "lessThan": "24.04.3",
              "versionType": "custom"
            }
          ],
          "packageName": "centreon-awie",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-01-05T15:15:44.177",
  "references": [
    {
      "url": "https://github.com/centreon/centreon/releases",
      "tags": [
        "Release Notes"
      ],
      "source": "bd4443e6-1eef-43f3-9886-25fc9ceeaae7"
    },
    {
      "url": "https://thewatch.centreon.com/latest-security-bulletins-64/cve-2025-15026-centreon-awie-critical-severity-5357",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "bd4443e6-1eef-43f3-9886-25fc9ceeaae7"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "bd4443e6-1eef-43f3-9886-25fc9ceeaae7",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs.\n\nThis issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de ausencia de autenticación para función crítica en Centreon Infra Monitoring centreon-awie (módulo de importación Awie) permite acceder a funcionalidad no debidamente restringida por ACLs.\n\nEste problema afecta a Infra Monitoring: desde 25.10.0 antes de 25.10.2, desde 24.10.0 antes de 24.10.3, desde 24.04.0 antes de 24.04.3."
    }
  ],
  "lastModified": "2026-09-30T23:10:00.237",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:centreon:awie:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C79E858-3E29-4916-9516-E1B7E3EF62B0",
              "versionEndExcluding": "24.04.3",
              "versionStartIncluding": "24.04.0"
            },
            {
              "criteria": "cpe:2.3:a:centreon:awie:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F2DA74C-7DB5-47F3-A8E8-7F55E4C73B7B",
              "versionEndExcluding": "24.10.3",
              "versionStartIncluding": "24.10.0"
            },
            {
              "criteria": "cpe:2.3:a:centreon:awie:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79268CBB-6F6E-45DF-89AA-0D47A201D600",
              "versionEndExcluding": "25.10.2",
              "versionStartIncluding": "25.10.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "bd4443e6-1eef-43f3-9886-25fc9ceeaae7"
}