OS Command Injection in Cacti - CVE-2023-39362
Published: September 5, 2023 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in lib/snmp.php. A remote user attacker can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Amazon Linux AMI
Debian Linux
Fedora
cacti
cacti (Debian package)
cacti-spine
How to mitigate CVE-2023-39362
cacti - update to 1.1.19-5.23
cacti (Debian package) - addressed in versions 1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1
cacti - addressed in versions 1.2.25-1.el7, 1.2.25-1.el8, 1.2.25-1.el9, 1.2.25-1.fc37, 1.2.25-1.fc38, 1.2.25-1.fc39
cacti-spine - addressed in versions 1.2.25-1.el7, 1.2.25-1.el8, 1.2.25-1.el9, 1.2.25-1.fc37, 1.2.25-1.fc38, 1.2.25-1.fc39
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Cacti
- Fedora 38 update for cacti, cacti-spine
- Fedora 37 update for cacti, cacti-spine
- Fedora 39 update for cacti, cacti-spine
- Fedora EPEL 7 update for cacti, cacti-spine
- Fedora EPEL 9 update for cacti, cacti-spine
- Fedora EPEL 8 update for cacti, cacti-spine
- Amazon Linux AMI update for cacti
- Debian update for cacti