OS Command Injection in Cacti - CVE-2020-8813
Published: February 24, 2020 / Updated: November 4, 2022
Vulnerability details
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the "graph_realtime.php" file. A remote user with graph real-time privilege can execute arbitrary OS commands on the target system via shell metacharacters in a cookie.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Fedora
SUSE Linux
Opensuse
cacti (Alpine package)
cacti
cacti-spine
SUSE Package Hub for SUSE Linux Enterprise
How to mitigate CVE-2020-8813
cacti (Alpine package) - update to 1.2.10-r0
cacti - addressed in versions 1.2.10-1.el7, 1.2.10-1.el8, 1.2.10-1.fc30, 1.2.10-1.fc31, 1.2.10-1.fc32
cacti-spine - addressed in versions 1.2.10-1.el7, 1.2.10-1.el8, 1.2.10-1.fc30, 1.2.10-1.fc31, 1.2.10-1.fc32
Links to Public Exploits and PoC-codes
- Exploit #8571 - CVE-2020-8813-Cacti-RCE-in-graph_realtime (CVE-2020-8813 - RCE through graph_realtime.php in Cacti 1.2.8) (November 4, 2022)
- Exploit #5751 - Cacti v1.2.8 - Unauthenticated Remote Code Execution (Metasploit) (June 17, 2021)
- Exploit #5758 - Cacti 1.2.8 - Unauthenticated Remote Code Execution (June 17, 2021)
- Exploit #5759 - Cacti 1.2.8 - Authenticated Remote Code Execution (June 17, 2021)
- Exploit #5721 - Open-AudIT Professional 3.3.1 - Remote Code Execution (June 17, 2021)
- Exploit #5399 - Cacti-CVE-2020-8813 () (May 12, 2021)
- Exploit #332 - CVE-2020-8813 (The official exploit for Cacti v1.2.8 Remote Code Execution CVE-2020-8813) (March 18, 2020)
- Exploit #1458 - Cacti 1.2.8 - Remote Code Execution (March 18, 2020)
External References
Related Security Bulletins
- Command Injection in Cacti
- Gentoo update for Cacti
- OS Command Injection in cacti (Alpine package)
- OpenSUSE Linux update for cacti, cacti-spine
- OpenSUSE Linux update for cacti, cacti-spine
- OpenSUSE Linux update for cacti, cacti-spine
- Fedora 30 update for cacti, cacti-spine
- Fedora 31 update for cacti, cacti-spine
- Fedora 32 update for cacti, cacti-spine
- Fedora EPEL 7 update for cacti, cacti-spine
- Fedora EPEL 8 update for cacti, cacti-spine