#VU70426 Improper Authorization in Cacti - CVE-2022-46169
Published: December 19, 2022 / Updated: October 25, 2024
Cacti
The Cacti Group, Inc.
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient authorization within the Remote Agent when handling HTTP requests with a custom Forwarded-For HTTP header. A remote non-authenticated attacker can send a specially crafted HTTP request to the affected instance and execute arbitrary OS commands on the server.
Remediation
External links
- https://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf
- https://github.com/Cacti/cacti/commit/b43f13ae7f1e6bfe4e8e56a80a7cd867cf2db52b
- https://github.com/Cacti/cacti/commit/a8d59e8fa5f0054aa9c6981b1cbe30ef0e2a0ec9
- https://github.com/Cacti/cacti/commit/7f0e16312dd5ce20f93744ef8b9c3b0f1ece2216
- https://www.zerodayinitiative.com/advisories/ZDI-23-093/