Security readout for executives and security teams
Plain-English summary
CVE-2019-19699 is an authenticated remote code execution issue in Centreon monitoring software through 19.10. An attacker already holding Centreon administrator access could abuse poller configuration behavior to reach system compromise, including code execution through a root-scheduled task path.
Executive priority
Treat this as high priority where legacy Centreon remains deployed. The attacker needs admin access, but successful abuse can cross from application administration into host-level compromise, increasing business impact for monitoring infrastructure.
Technical view
The CVE describes abuse of Centreon Pollers misconfiguration. A Centreon Web Interface admin can define a custom command, set it as the Pollers Post-Restart Command, and trigger it through poller configuration export. The reported impact stems from Apache-user write access to an executable later run by root.
Likely exposure
Exposure is most relevant for organizations running Centreon Infrastructure Monitoring Software through version 19.10, especially where the web interface is reachable by many administrators or externally accessible management networks. The bundle does not provide CPEs or a complete affected-version matrix.
Exploitation context
The bundle does not show CISA KEV listing or confirmed active exploitation. It does include public researcher references, including a GitHub repository. Exploitation requires Centreon Web Interface administrator access and a poller configuration export trigger.
Researcher notes
Evidence is limited to the CVE description and referenced public materials. No CVSS, CWE, CPE, vendor advisory, or explicit fixed version is included in the bundle. Avoid claiming unauthenticated exploitation or active exploitation from these sources alone.
Mitigation direction
- Check Centreon vendor guidance and upgrade beyond affected versions where applicable.
- Restrict Centreon administrator access to trusted users and protected management networks.
- Audit Pollers Post-Restart Command settings for unexpected or unauthorized commands.
- Review permissions on files executed by root-scheduled Centreon cron paths.
- Remove unused admin accounts and enforce strong authentication controls.
Validation and detection
- Inventory Centreon deployments and confirm whether any are version 19.10 or earlier.
- Review Centreon administrator account history and current role assignments.
- Inspect poller configuration for nonstandard post-restart command entries.
- Check whether Apache-writable files are executed by root-scheduled tasks.
- Review system logs around poller configuration exports and scheduled execution times.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Execution behavior lookup
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2019-19699 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://download.centreon.com/CVE reference · x_refsource_MISC
- https://www.centreon.com/CVE reference · x_refsource_MISC
- https://twitter.com/SpengeSec/status/1204418071764463618CVE reference · x_refsource_MISC
- https://spenge.pw/cves/CVE reference · x_refsource_MISC
- https://github.com/SpengeSec/CVE-2019-19699CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
