PT-2024-10486 · Cacti+1 · Cacti+1

Tayfunyelim

·

Published

2024-08-26

·

Updated

2025-04-17

·

CVE-2024-45598

CVSS v2.0

8.0

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cacti versions prior to 1.2.29
Description The issue concerns an open-source performance and fault management framework. An administrator can modify the Poller Standard Error Log Path parameter to point to a local file on the server, allowing its content to be displayed on the web UI. This can lead to unauthorized access to sensitive information. The vulnerability is fixed in version 1.2.29.
Recommendations For versions prior to 1.2.29, update to version 1.2.29 to resolve the issue. As a temporary workaround, consider restricting access to the Poller Standard Error Log Path parameter to prevent unauthorized modifications.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3834
ALT-PU-2025-5333
BDU:2025-01037
CVE-2024-45598
DLA-4048-1
DSA-5862-1
GHSA-PV2C-97PP-VXWG

Affected Products

Alt Linux
Cacti