cbcvebase.
CVE-2024-34340
published 2024-05-14

CVE-2024-34340: Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their…

PriorityP353critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.12%
62.5th percentile
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls `compat_password_verify`. In `compat_password_verify`, `password_verify` is called if there is it, else use `md5`. `password_verify` and `password_hash` are supported on PHP < 5.5.0, following PHP manual. The vulnerability is in `compat_password_verify`. Md5-hashed user input is compared with correct password in database by `$md5 == $hash`. It is a loose comparison, not `===`. It is a type juggling vulnerability. Version 1.2.27 contains a patch for the issue.

Affected

7 ranges
VendorProductVersion rangeFixed in
cacticacti< 1.2.271.2.27
cacticacti>= 0 < 1.2.16+ds1-2+deb11u41.2.16+ds1-2+deb11u4
cacticacti>= 0 < 1.2.24+ds1-1+deb12u31.2.24+ds1-1+deb12u3
cacticacti>= 0 < 1.2.27+ds1-11.2.27+ds1-1
cacticacti>= 0 < 1.2.27+ds1-11.2.27+ds1-1
debiancacti< cacti 1.2.24+ds1-1+deb12u3 (bookworm)cacti 1.2.24+ds1-1+deb12u3 (bookworm)
fedoraprojectfedora

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_ubuntu9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.