Improper Authentication in Cacti - CVE-2022-0730

 

Improper Authentication in Cacti - CVE-2022-0730

Published: September 29, 2022


Vulnerability identifier: #VU67763
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0730
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing LDAP authentication requests. A remote attacker can bypass LDAP authentication with certain credentials types and gain unauthorized access to the application.


Affected software

Cacti
Amazon Linux AMI
Debian Linux
Fedora
cacti
cacti (Debian package)
cacti-spine

How to mitigate CVE-2022-0730

Install updates from vendor's website.

Cacti - update to 1.2.20
cacti - update to 1.1.19-2.19
cacti (Debian package) - update to 1.2.16+ds1-2+deb11u1
cacti - addressed in versions 1.2.20-1.el7, 1.2.20-1.el8, 1.2.20-1.fc34, 1.2.20-1.fc35, 1.2.20-1.fc36
cacti-spine - addressed in versions 1.2.20-1.el7, 1.2.20-1.el8, 1.2.20-1.fc34, 1.2.20-1.fc35, 1.2.20-1.fc36

External References

Related Security Bulletins