Lucene search

K
amazonAmazonALAS-2024-1915
HistoryFeb 01, 2024 - 7:33 p.m.

Important: cacti

2024-02-0119:33:00
alas.aws.amazon.com
11
cacti
snmp
blind sql injection

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

Low

EPSS

0.001

Percentile

42.8%

Issue Overview:

Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNMP Notification Receivers feature in the file 'managers.php'. An authenticated attacker with the “Settings/Utilities” permission can send a crafted HTTP GET request to the endpoint '/cacti/managers.php' with an SQLi payload in the 'selected_graphs_array' HTTP GET parameter. As of time of publication, no patched versions exist. (CVE-2023-51448)

Affected Packages:

cacti

Issue Correction:
Run yum update cacti to update your system.

New Packages:

noarch:  
    cacti-1.1.19-6.24.amzn1.noarch  
  
src:  
    cacti-1.1.19-6.24.amzn1.src  

Additional References

Red Hat: CVE-2023-51448

Mitre: CVE-2023-51448

OSVersionArchitecturePackageVersionFilename
Amazon Linux1noarchcacti< 1.1.19-6.24.amzn1cacti-1.1.19-6.24.amzn1.noarch.rpm

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

Low

EPSS

0.001

Percentile

42.8%