← Back to browse · API

CVE-2023-39362

Severity
HIGH
CVSS
7.2
EPSS
0.82186
Risk score
57.57
CISA KEV
No
PoC
No
Published
2023-09-05
Modified
2025-02-27
First seen
2026-08-07
Aliases
EUVD-2023-43088
Products
Cacti:cacti < 1.2.25
Sources
euvd EUVD-2023-43088

Description

Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server. The `lib/snmp.php` file has a set of functions, with similar behavior, that accept in input some variables and place them into an `exec` call without a proper escape or validation. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

References