Improper Authentication in Cacti - CVE-2022-0730
Published: September 29, 2022
Vulnerability identifier: #VU67763
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0730
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing LDAP authentication requests. A remote attacker can bypass LDAP authentication with certain credentials types and gain unauthorized access to the application.
Affected software
Cacti
Amazon Linux AMI
Debian Linux
Fedora
cacti
cacti (Debian package)
cacti-spine
Amazon Linux AMI
Debian Linux
Fedora
cacti
cacti (Debian package)
cacti-spine
How to mitigate CVE-2022-0730
Install updates from vendor's website.
Cacti - update to 1.2.20
cacti - update to 1.1.19-2.19
cacti (Debian package) - update to 1.2.16+ds1-2+deb11u1
cacti - addressed in versions 1.2.20-1.el7, 1.2.20-1.el8, 1.2.20-1.fc34, 1.2.20-1.fc35, 1.2.20-1.fc36
cacti-spine - addressed in versions 1.2.20-1.el7, 1.2.20-1.el8, 1.2.20-1.fc34, 1.2.20-1.fc35, 1.2.20-1.fc36
cacti - update to 1.1.19-2.19
cacti (Debian package) - update to 1.2.16+ds1-2+deb11u1
cacti - addressed in versions 1.2.20-1.el7, 1.2.20-1.el8, 1.2.20-1.fc34, 1.2.20-1.fc35, 1.2.20-1.fc36
cacti-spine - addressed in versions 1.2.20-1.el7, 1.2.20-1.el8, 1.2.20-1.fc34, 1.2.20-1.fc35, 1.2.20-1.fc36
External References
- https://github.com/Cacti/cacti/issues/4562
- https://lists.debian.org/debian-lts-announce/2022/03/msg00038.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZJERS4NYIGJUXEGT6ATUQA4CBYBRDLRA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RVOALVZSCBFNOAAZVHTJFSFB7UDSNYQ2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZH67CCORDEYFG7NL7G6UH47PAV2PU7BA/