CVE-2025-22604
published 2025-01-27CVE-2025-22604: Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed…
PriorityP350high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
5.29%
91.7th percentile
Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed OIDs in the response. When processed by ss_net_snmp_disk_io() or ss_net_snmp_disk_bytes(), a part of each OID will be used as a key in an array that is used as part of a system command, causing a command execution vulnerability. This vulnerability is fixed in 1.2.29.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | < 1.2.29 | 1.2.29 |
| cacti | cacti | <= 1.2.8 | — |
| cacti | cacti | >= 0 < 1.2.16+ds1-2+deb11u5 | 1.2.16+ds1-2+deb11u5 |
| cacti | cacti | >= 0 < 1.2.24+ds1-1+deb12u5 | 1.2.24+ds1-1+deb12u5 |
| cacti | cacti | >= 0 < 1.2.28+ds1-4 | 1.2.28+ds1-4 |
| cacti | cacti | >= 0 < 1.2.28+ds1-4 | 1.2.28+ds1-4 |
| debian | cacti | < cacti 1.2.24+ds1-1+deb12u5 (bookworm) | cacti 1.2.24+ds1-1+deb12u5 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerable functions are ss_net_snmp_disk_io() and ss_net_snmp_disk_bytes() — monitor for anomalous or malformed OID values being processed by these Cacti functions, as a portion of the OID is used as an array key in a system command ↗
- →The attack vector is injection of malformed OIDs in multi-line SNMP responses — inspect SNMP poll results ingested by Cacti for unexpected characters or shell metacharacters embedded within OID strings ↗
- ·Exploitation requires authentication — prioritize monitoring authenticated Cacti user sessions and restrict SNMP data source permissions to trusted users only ↗
- ·Fixed in Cacti 1.2.29 upstream; Debian-specific fixes vary by release (bookworm: 1.2.24+ds1-1+deb12u5, bullseye: 1.2.16+ds1-2+deb11u5, forky/sid/trixie: 1.2.28+ds1-4) — verify the exact installed package version matches the patched version for your distribution ↗
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv7.2HIGH
vendor_debian9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2025-22604: cacti - Cacti is an open source performance and fault management framework. Due to a fla...
vendor_debian·2025·CVSS 9.1
CVE-2025-22604 [CRITICAL] CVE-2025-22604: cacti - Cacti is an open source performance and fault management framework. Due to a fla...
Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed OIDs in the response. When processed by ss_net_snmp_disk_io() or ss_net_snmp_disk_bytes(), a part of each OID will be used as a key in an array that is used as part of a system command, causing a command execution vulnerability. This vulnerability is fixed in 1.2.29.
Scope: local
bookworm: resolved (fixed in 1.2.24+ds1-1+deb12u5)
bullseye: resolved (fixed in 1.2.16+ds1-2+deb11u5)
forky: resolved (fixed in 1.2.28+ds1-4)
sid: resolved (fixed in 1.2.28+ds1-4)
trixie: resolved (fixed in 1.2.28+ds1-4)
OSV
CVE-2025-22604: Cacti is an open source performance and fault management framework
osv·2025-01-27·CVSS 7.2
CVE-2025-22604 [HIGH] CVE-2025-22604: Cacti is an open source performance and fault management framework
Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed OIDs in the response. When processed by ss_net_snmp_disk_io() or ss_net_snmp_disk_bytes(), a part of each OID will be used as a key in an array that is used as part of a system command, causing a command execution vulnerability. This vulnerability is fixed in 1.2.29.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-27
Published