PT-2019-5225 · Cacti+2 · Cacti+2

George-Karo

·

Published

2019-09-23

·

Updated

2025-01-24

·

CVE-2019-16723

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.7
Description The issue is related to an authorization check error in the local graph id function of the Cacti server monitoring system. This allows a remote attacker to potentially access confidential data by bypassing authorization checks for viewing graphs. The exploitation involves making a direct request to the graph json.php endpoint with a modified local graph id parameter.
Recommendations For Cacti versions prior to 1.2.7, update to version 1.2.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the graph json.php endpoint to minimize the risk of exploitation.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1488
ALT-PU-2020-3430
ALT-PU-2025-1813
BDU:2020-01954
CVE-2019-16723
DSA-4604-1
OPENSUSE-SU-2020:0272-1
OPENSUSE-SU-2020:0284-1
OPENSUSE-SU-2020:0558-1
OPENSUSE-SU-2020:0565-1
OPENSUSE-SU-2020_0272-1
OPENSUSE-SU-2020_0558-1
OPENSUSE-SU-2024:10670-1

Affected Products

Alt Linux
Cacti
Suse