CVE-2016-2313
published 2016-04-13CVE-2016-2313: auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a…
PriorityP353high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.69%
84.2th percentile
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | < 1.0.0 | 1.0.0 |
| cacti | cacti | <= 0.8.8f | — |
| cacti | cacti | >= 0 < 0.8.8h+ds1-5 | 0.8.8h+ds1-5 |
| cacti | cacti | >= 0 < 0.8.8g+ds1-1 | 0.8.8g+ds1-1 |
| cacti | cacti | >= 0 < 0.8.8h+ds1-5 | 0.8.8h+ds1-5 |
| cacti | cacti | >= 0 < 0.8.8g+ds1-1 | 0.8.8g+ds1-1 |
| cacti | cacti | >= 0 < 0.8.8h+ds1-5 | 0.8.8h+ds1-5 |
| cacti | cacti | >= 0 < 0.8.8g+ds1-1 | 0.8.8g+ds1-1 |
| cacti | cacti | >= 0 < 0.8.8h+ds1-5 | 0.8.8h+ds1-5 |
| cacti | cacti | >= 0 < 0.8.8g+ds1-1 | 0.8.8g+ds1-1 |
| debian | cacti | < cacti 0.8.8h+ds1-5 (bookworm) | cacti 0.8.8h+ds1-5 (bookworm) |
| debian | cacti | < cacti 0.8.8g+ds1-1 (bookworm) | cacti 0.8.8g+ds1-1 (bookworm) |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-72gr-g5cr-jq69: auth_login
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2016-10700 [HIGH] GHSA-72gr-g5cr-jq69: auth_login
auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database, because the guest user is not considered. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-2313.
GHSA
GHSA-hqj3-mvg5-35g5: auth_login
ghsa_unreviewed·2022-05-14
CVE-2016-2313 [HIGH] GHSA-hqj3-mvg5-35g5: auth_login
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
OSV
CVE-2016-10700: auth_login
osv·2017-11-24·CVSS 8.8
CVE-2016-10700 [HIGH] CVE-2016-10700: auth_login
auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database, because the guest user is not considered. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-2313.
OSV
CVE-2016-2313: auth_login
osv·2016-04-13·CVSS 8.8
CVE-2016-2313 [HIGH] CVE-2016-2313: auth_login
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
Debian
CVE-2016-10700: cacti - auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use w...
vendor_debian·2016·CVSS 8.8
CVE-2016-10700 [HIGH] CVE-2016-10700: cacti - auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use w...
auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database, because the guest user is not considered. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-2313.
Scope: local
bookworm: resolved (fixed in 0.8.8h+ds1-5)
bullseye: resolved (fixed in 0.8.8h+ds1-5)
forky: resolved (fixed in 0.8.8h+ds1-5)
sid: resolved (fixed in 0.8.8h+ds1-5)
trixie: resolved (fixed in 0.8.8h+ds1-5)
Debian
CVE-2016-2313: cacti - auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use ...
vendor_debian·2016·CVSS 8.8
CVE-2016-2313 [HIGH] CVE-2016-2313: cacti - auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use ...
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
Scope: local
bookworm: resolved (fixed in 0.8.8g+ds1-1)
bullseye: resolved (fixed in 0.8.8g+ds1-1)
forky: resolved (fixed in 0.8.8g+ds1-1)
sid: resolved (fixed in 0.8.8g+ds1-1)
trixie: resolved (fixed in 0.8.8g+ds1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2313 cacti: authentication bypass
bugzilla·2016-02-11·CVSS 8.8
CVE-2016-2313 [HIGH] CVE-2016-2313 cacti: authentication bypass
CVE-2016-2313 cacti: authentication bypass
Accessing cacti using a user name not the cacti database fills the log with
database error messages and allows complete access to everything, including the
user administration pages. The bug is in auth_login.php which fails to check
the query actually found any data or not.
Upstream bug report:
http://bugs.cacti.net/view.php?id=2656
Upstream fix:
http://svn.cacti.net/viewvc?view=rev&revision=7770
Discussion:
Created cacti tracking bugs for this issue:
Affects: epel-all [bug 1306530]
---
CVE assignment:
http://seclists.org/oss-sec/2016/q1/305
Bugzilla
CVE-2016-2313 cacti: authentication bypass [epel-all]
bugzilla·2016-02-11·CVSS 8.8
CVE-2016-2313 [HIGH] CVE-2016-2313 cacti: authentication bypass [epel-all]
CVE-2016-2313 cacti: authentication bypass [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EPEL. While
http://bugs.cacti.net/view.php?id=2656http://lists.opensuse.org/opensuse-updates/2016-02/msg00077.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00078.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00080.htmlhttp://www.cacti.net/release_notes_0_8_8g.phphttp://www.securitytracker.com/id/1037745https://security.gentoo.org/glsa/201607-05https://security.gentoo.org/glsa/201711-10http://bugs.cacti.net/view.php?id=2656http://lists.opensuse.org/opensuse-updates/2016-02/msg00077.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00078.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00080.htmlhttp://www.cacti.net/release_notes_0_8_8g.phphttp://www.securitytracker.com/id/1037745https://security.gentoo.org/glsa/201607-05https://security.gentoo.org/glsa/201711-10
2016-04-13
Published