cbcvebase.
CVE-2019-17358
published 2019-12-12

CVE-2019-17358: Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated…

PriorityP344high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
3.00%
86.0th percentile
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module.

Affected

8 ranges
VendorProductVersion rangeFixed in
cacticacti<= 1.2.7
cacticacti>= 0 < 1.2.8+ds1-11.2.8+ds1-1
cacticacti>= 0 < 1.2.8+ds1-11.2.8+ds1-1
cacticacti>= 0 < 1.2.8+ds1-11.2.8+ds1-1
cacticacti>= 0 < 1.2.8+ds1-11.2.8+ds1-1
debiancacti< cacti 1.2.8+ds1-1 (bookworm)cacti 1.2.8+ds1-1 (bookworm)
debiandebian_linux
opensuseleap

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.