vendor:
Cacti
by:
Antonio Francesco Sardella
6.1
CVSS
HIGH
Authenticated command injection
77
CWE
Product Name: Cacti
Affected Version From: Cacti 1.2.24
Affected Version To: Cacti 1.2.24
Patch Exists: YES
Related CWE: CVE-2023-39362
CPE: a:cacti:cacti:1.2.24
Platforms Tested: Cacti 1.2.24 installed on 'php:7.4.33-apache' Docker container
2023
Cacti 1.2.24 โ Authenticated command injection when using SNMP options
In Cacti 1.2.24, under certain conditions, an authenticated privileged user can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server.
Mitigation:
Update to the latest version of Cacti (1.2.25 or higher) which includes a patch for this vulnerability.