PT-2020-19487 · Cacti+2 · Cacti+2
0Xfatty
·
Published
2020-01-20
·
Updated
2025-01-24
·
CVE-2020-7237
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cacti version 1.2.8
Description
The issue allows remote code execution by privileged users through shell metacharacters in the Performance Boost Debug Log field of poller automation.php. This occurs when a new poller cycle begins, requiring the attacker to be authenticated and have access to modify the Performance Settings of the product.
Recommendations
For Cacti version 1.2.8, consider disabling access to the Performance Boost Debug Log field in poller automation.php until a patch is available, and restrict modifications to the Performance Settings to trusted users only.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Cacti
Suse