PT-2024-6665 · Cacti+1 · Cacti+1

Tayfunyelim

·

Published

2023-07-13

·

Updated

2025-02-11

·

CVE-2024-43363

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Cacti versions prior to 1.2.28
Description: The issue is related to incorrect code generation management in the Cacti network monitoring tool. An admin user can create a device with a malicious hostname containing PHP code, allowing for log poisoning and potentially leading to Remote Code Execution (RCE). This can be achieved by completing only step 5 of the installation process. The estimated number of potentially affected devices worldwide is not provided. There are no known real-world incidents where this issue was exploited.
Recommendations: For versions prior to 1.2.28, upgrade to version 1.2.28 or later to address the issue. As a temporary workaround, consider restricting access to the log files to minimize the risk of exploitation. Avoid using malicious hostnames containing PHP code in the device creation process until the issue is resolved.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4394
ALT-PU-2023-4396
ALT-PU-2023-5196
ALT-PU-2024-14329
ALT-PU-2024-14440
ALT-PU-2024-17822
ALT-PU-2025-1813
BDU:2024-07867
CVE-2024-43363
DLA-4048-1
DSA-5862-1
GHSA-GXQ4-MV8H-6QJ4

Affected Products

Alt Linux
Cacti