Improper Authorization in Cacti - CVE-2022-46169

 

Improper Authorization in Cacti - CVE-2022-46169

Published: December 19, 2022 / Updated: October 25, 2024


Vulnerability identifier: #VU70426
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46169
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient authorization within the Remote Agent when handling HTTP requests with a custom Forwarded-For HTTP header. A remote non-authenticated attacker can send a specially crafted HTTP request  to the affected instance and execute arbitrary OS commands on the server.


Affected software

Cacti
Debian Linux
Amazon Linux AMI
Fedora
Ubuntu
cacti (Ubuntu package)
cacti
cacti (Debian package)
cacti-1.2.23-1.el7 cacti-spine
cacti-1.2.23-1.el8 cacti-spine
cacti-1.2.23-1.el9 cacti-spine
cacti-1.2.23-1.fc36 cacti-spine
cacti-1.2.23-1.fc37 cacti-spine

How to mitigate CVE-2022-46169

Install updates from vendor's website.

Cacti - update to 1.2.23
cacti (Ubuntu package) - update to Ubuntu Pro
cacti - update to 1.1.19-2.20
cacti (Debian package) - update to 1.2.16+ds1-2+deb11u1
cacti-1.2.23-1.el7 cacti-spine - update to 1.2.23-1.el7
cacti-1.2.23-1.el8 cacti-spine - update to 1.2.23-1.el8
cacti-1.2.23-1.el9 cacti-spine - update to 1.2.23-1.el9
cacti-1.2.23-1.fc36 cacti-spine - update to 1.2.23-1.fc36
cacti-1.2.23-1.fc37 cacti-spine - update to 1.2.23-1.fc37

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins