Improper Authorization in Cacti - CVE-2022-46169
Published: December 19, 2022 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient authorization within the Remote Agent when handling HTTP requests with a custom Forwarded-For HTTP header. A remote non-authenticated attacker can send a specially crafted HTTP request to the affected instance and execute arbitrary OS commands on the server.
Affected software
Debian Linux
Amazon Linux AMI
Fedora
Ubuntu
cacti (Ubuntu package)
cacti
cacti (Debian package)
cacti-1.2.23-1.el7 cacti-spine
cacti-1.2.23-1.el8 cacti-spine
cacti-1.2.23-1.el9 cacti-spine
cacti-1.2.23-1.fc36 cacti-spine
cacti-1.2.23-1.fc37 cacti-spine
How to mitigate CVE-2022-46169
cacti (Ubuntu package) - update to Ubuntu Pro
cacti - update to 1.1.19-2.20
cacti (Debian package) - update to 1.2.16+ds1-2+deb11u1
cacti-1.2.23-1.el7 cacti-spine - update to 1.2.23-1.el7
cacti-1.2.23-1.el8 cacti-spine - update to 1.2.23-1.el8
cacti-1.2.23-1.el9 cacti-spine - update to 1.2.23-1.el9
cacti-1.2.23-1.fc36 cacti-spine - update to 1.2.23-1.fc36
cacti-1.2.23-1.fc37 cacti-spine - update to 1.2.23-1.fc37
Links to Public Exploits and PoC-codes
- Exploit #10701 - Cacti v1.2.22 - Remote Command Execution (RCE) (October 25, 2024)
- Exploit #9315 - CVE-2022-46169-Exploit () (September 11, 2023)
- Exploit #9314 - PricklyPwn (An advanced RCE tool tailored for exploiting a vulnerability in Cacti v1.2.22. Crafted with precision, this utility aids security researchers in analyzing and understanding the depth of the CVE-2022-46169 flaw. Use responsibly and ethically.) (September 11, 2023)
- Exploit #9239 - PoCs (Containing PoC's) (August 8, 2023)
- Exploit #9089 - CVE-2022-46169_POC (RCE POC for CVE-2022-46169) (June 6, 2023)
- Exploit #9070 - CVE-2022-46169 (Exploit for cacti version 1.2.22) (May 14, 2023)
- Exploit #9069 - ImprovedShell-for-CVE-2022-46169 (This Python script aids in exploiting CVE-2022-46169 by automating payload delivery and response handling. It starts an HTTP server, listens for requests, and enables command input for real-time interaction with a vulnera (May 14, 2023)
- Exploit #9067 - CVE-Scripts (Containing PoC's) (May 14, 2023)
- Exploit #9050 - CVE-2022-46169 (? Python Exploit for CVE-2022-46169) (May 7, 2023)
- Exploit #9038 - CVE-2022-46169 (CVE-2022-46169) (May 4, 2023)
- Exploit #9036 - CVE-2022-46169 (Proof of concept / CTF script for exploiting CVE-2022-46169 in Cacti, versions >=1.2.22) (May 4, 2023)
- Exploit #9029 - CVE-2022-46169 (Exploit for cacti version 1.2.22) (May 2, 2023)
- Exploit #9028 - CVE-2022-46169-CACTI-1.2.22 (This is a exploit of CVE-2022-46169 to cacti 1.2.22. This exploit allows through an RCE to obtain a reverse shell on your computer.) (May 2, 2023)
- Exploit #9027 - RCE-Cacti-1.2.22 (Este es un código del exploit CVE-2022-46169, que recree utilizando Python3! Si por ahí estás haciendo una máquina de HTB, esto te puede ser útil... ?✨ ) (May 2, 2023)
- Exploit #9025 - cacti-CVE-2022-46169 (Exploit for cacti version 1.2.22) (May 1, 2023)
- Exploit #9022 - CVE-2022-46169_unauth_remote_code_execution (Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0) (April 30, 2023)
- Exploit #8982 - CVE-2022-46169 (Fixed exploit for CVE-2022-46169 (originally from https://www.exploit-db.com/exploits/51166)) (April 13, 2023)
- Exploit #8954 - cacti-rce-cve-2022-46169-vulnerable-application (WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2022-46169). Run it at your own risk!) (April 3, 2023)
- Exploit #8952 - CVE-2022-46169 (CVE-2022-46169) (March 31, 2023)
- Exploit #8906 - cacti-cve-2022-46169-exploit (This is poc of CVE-2022-46169 authentication bypass and remote code execution) (March 13, 2023)
- Exploit #8762 - Cacti 1.2.22 unauthenticated command injection (January 23, 2023)
- Exploit #8743 - CVE-2022-46169 (Cacti: Unauthenticated Remote Code Execution Exploit in Ruby ) (January 16, 2023)
- Exploit #8737 - CVE-2022-46169 (Exploit to CVE-2022-46169 vulnerability) (January 14, 2023)
- Exploit #8712 - CVE-2022-46169 (PoC for CVE-2022-46169 - Unauthenticated RCE on Cacti <= 1.2.22) (January 5, 2023)
- Exploit #8708 - CVE-2022-46169 (Cacti Unauthenticated Command Injection) (January 3, 2023)
- Exploit #8683 - CVE-2022-46169 (CVE-2022-46169 - Cacti Blind Remote Code Execution (Pre-Auth)) (December 19, 2022)
- Exploit #8682 - CVE-2022-46169 (CVE-2022-46169 Cacti remote_agent.php Unauthenticated Command Injection.) (December 19, 2022)
External References
- https://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf
- https://github.com/Cacti/cacti/commit/b43f13ae7f1e6bfe4e8e56a80a7cd867cf2db52b
- https://github.com/Cacti/cacti/commit/a8d59e8fa5f0054aa9c6981b1cbe30ef0e2a0ec9
- https://github.com/Cacti/cacti/commit/7f0e16312dd5ce20f93744ef8b9c3b0f1ece2216
- https://www.zerodayinitiative.com/advisories/ZDI-23-093/
Related Security Bulletins
- Remote command execution in Cacti
- Debian update for cacti
- Amazon Linux AMI update for cacti
- Fedora 36 update for cacti-1.2.23-1.fc36 cacti-spine
- Fedora 37 update for cacti-1.2.23-1.fc37 cacti-spine
- Fedora EPEL 7 update for cacti-1.2.23-1.el7 cacti-spine
- Fedora EPEL 8 update for cacti-1.2.23-1.el8 cacti-spine
- Fedora EPEL 9 update for cacti-1.2.23-1.el9 cacti-spine
- Ubuntu update for cacti