PT-2025-1299 · Cacti+1 · Cacti+1

U32I

·

Publicado

2025-01-26

·

Atualizado

2026-03-09

·

CVE-2025-22604

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.29 Cacti versions prior to 1.2.24+ds1-1+deb12u5 Cacti versions prior to 1.2.16+ds1-2+deb11u5
Description Cacti, a web interface for graphing of monitoring systems, contains a critical flaw in its multi-line SNMP result parser. This allows authenticated users to inject malformed Object Identifier (OID) values in SNMP responses. When processed by the ss net snmp disk io() or ss net snmp disk bytes() functions, a portion of each OID is used as a key in an array that is then used as part of a system command, leading to remote code execution. Approximately 179,000 instances of Cacti are discoverable online.
Recommendations Upgrade to Cacti version 1.2.29 or later. Upgrade to Cacti version 1.2.24+ds1-1+deb12u5 or later. Upgrade to Cacti version 1.2.16+ds1-2+deb11u5 or later.

Exploit

Correção

RCE

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2025-3834
ALT-PU-2025-5333
BDU:2025-00856
CVE-2025-22604
DLA-4048-1
DSA-5862-1
GHSA-C5J8-JXJ3-HH36

Produtos afetados

Alt Linux
Cacti