PT-2023-4942 · Cacti+2 · Cacti+2

K0Pak4

·

Publicado

2023-09-05

·

Atualizado

2025-01-24

·

CVE-2023-30534

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cacti versions 1.2.24
Description The issue is related to insecure deserialization in Cacti, specifically within the host new graphs save function in graphs new.php. This is due to the use of the unserialize function without sanitizing user input. Although a viable gadget chain exists in Cacti's vendor directory, the necessary gadgets are not included, making the insecure deserializations not exploitable. It is estimated that about 16,674 results are potentially affected. The issue has been addressed in version 1.2.25.
Recommendations For Cacti version 1.2.24, upgrade to version 1.2.25 to resolve the issue. As a temporary workaround, consider restricting access to the graphs new.php file or disabling the host new graphs save function until the upgrade can be applied. Avoid using the unserialize function without proper sanitization of user input.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-7619
ALT-PU-2023-7621
ALT-PU-2024-7120
ALT-PU-2025-1813
BDU:2023-05455
CVE-2023-30534
GHSA-77RF-774J-6H3P
OPENSUSE-SU-2023:0275-1
OPENSUSE-SU-2024:13203-1

Produtos afetados

Alt Linux
Cacti
Debian