CVE-2014-2327 — Cross-Site Request Forgery in Cacti
Severity
6.8MEDIUMNVD
EPSS
0.4%
top 37.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 23
Latest updateMay 14
Description
Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4
Affected Packages4 packages
Also affects: Debian Linux 7.0, 8.0
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2014-2327: cacti - Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and ear...↗2014
💬Community
4Bugzilla▶
CVE-2015-2327 pcre: infinite recursion compiling pattern with zero-repeated groups that include recursive back reference (8.36/19)↗2015-11-25
Bugzilla▶
CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [fedora-all]↗2014-04-01
Bugzilla▶
CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [epel-all]↗2014-04-01
Bugzilla▶
CVE-2014-2326 CVE-2014-2327 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom↗2014-03-28