Lucene search

K
freebsdFreeBSD59C284F4-8D2E-11ED-9CE0-B42E991FC52E
HistoryDec 05, 2022 - 12:00 a.m.

net-mgmt/cacti is vulnerable to remote command injection

2022-12-0500:00:00
vuxml.freebsd.org
17
net-mgmt
cacti
command injection
vulnerable
remote
arbitrary code
unauthenticated
data source
monitored device
unix

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.964 High

EPSS

Percentile

99.6%

cacti team reports:

    A command injection vulnerability allows an
    unauthenticated user to execute arbitrary code on a server
    running Cacti, if a specific data source was selected for
    any monitored device.
OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchcacti< 1.2.23UNKNOWN

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.964 High

EPSS

Percentile

99.6%