vendor:
Cacti
by:
Antonio Francesco Sardella
6.1
CVSS
HIGH
Authenticated command injection
78
CWE
Product Name: Cacti
Affected Version From: 1.2.24
Affected Version To: 1.2.24
Patch Exists: YES
Related CWE: CVE-2023-39362
CPE: a:cacti:cacti:1.2.24
Platforms Tested: Cacti 1.2.24 installed on 'php:7.4.33-apache' Docker container
2023
Cacti 1.2.24 – Authenticated command injection when using SNMP options
Under certain conditions, an authenticated privileged user can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server.
Mitigation:
Upgrade to Cacti version 1.2.25 or later.