Debian Cacti vulnerabilities

160 known vulnerabilities affecting debian/cacti.

Total CVEs
160
CISA KEV
1
actively exploited
Public exploits
26
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH50MEDIUM72LOW28

Vulnerabilities

Page 2 of 8
CVE-2024-31444MEDIUMCVSS 4.6fixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2024
CVE-2024-31444 [MEDIUM] CVE-2024-31444: cacti - Cacti provides an operational monitoring and fault management framework. Prior t... Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the HTML statement in `form_confirm()` function from `lib/html.php` , finally resulting in cross-site scripting. V
debian
CVE-2024-31443MEDIUMCVSS 5.7fixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2024
CVE-2024-31443 [MEDIUM] CVE-2024-31443: cacti - Cacti provides an operational monitoring and fault management framework. Prior t... Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_pane_tree()` function from `lib/html.php` , finally resulting in cross-site scripting. Version 1.2.27 contains a patch
debian
CVE-2024-29894MEDIUMCVSS 5.4fixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2024
CVE-2024-29894 [MEDIUM] CVE-2024-29894: cacti - Cacti provides an operational monitoring and fault management framework. Version... Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js to fix CVE-2023-50250 (among others). However, it still generates the code out of unesca
debian
CVE-2024-31460MEDIUMCVSS 6.5fixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2024
CVE-2024-31460 [MEDIUM] CVE-2024-31460: cacti - Cacti provides an operational monitoring and fault management framework. Prior t... Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_nodes()` function from `lib/api_automation.php` , finally resulting in SQL injection. Using SQL based secondary injection
debian
CVE-2024-54146LOWCVSS 7.6fixed in cacti 1.2.28+ds1-4 (forky)2024
CVE-2024-54146 [HIGH] CVE-2024-54146: cacti - Cacti is an open source performance and fault management framework. Cacti has a ... Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the template function of host_templates.php using the graph_template parameter. This vulnerability is fixed in 1.2.29. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 1.2.28+ds1-4) sid: resolved (fixed in 1.2.28+ds1-4) trixie: res
debian
CVE-2024-30268LOWCVSS 6.12024
CVE-2024-30268 [MEDIUM] CVE-2024-30268: cacti - Cacti provides an operational monitoring and fault management framework. A refle... Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of administrator and other users and fake their login using obtained cookies. This issue is fixed in commit a38b9046e9772612fda847b46308f9391a49891e. Scope: local bookworm: resolved bullsey
debian
CVE-2024-29895LOWCVSS 10.0PoC2024
CVE-2024-29895 [CRITICAL] CVE-2024-29895: cacti - Cacti provides an operational monitoring and fault management framework. A comma... Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `On`. In `cmd_realtime.php` line 119, the `$poller_id` used as part of the command execution is sourced from `$_SERVE
debian
CVE-2023-39361CRITICALCVSS 9.8PoCfixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39361 [CRITICAL] CVE-2023-39361: cacti - Cacti is an open source operational monitoring and fault management framework. A... Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit
debian
CVE-2023-49084HIGHCVSS 8.0PoCfixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2023
CVE-2023-49084 [HIGH] CVE-2023-49084: cacti - Cacti is a robust performance and fault management framework and a frontend to R... Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary code on the server. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the
debian
CVE-2023-39358HIGHCVSS 8.8fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39358 [HIGH] CVE-2023-39358: cacti - Cacti is an open source operational monitoring and fault management framework. A... Cacti is an open source operational monitoring and fault management framework. An authenticated SQL injection vulnerability was discovered which allows authenticated users to perform privilege escalation and remote code execution. The vulnerability resides in the `reports_user.php` file. In `ajax_get_branches`, the `tree_id` parameter is passed to the `reports_get_bra
debian
CVE-2023-39359HIGHCVSS 8.8fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39359 [HIGH] CVE-2023-39359: cacti - Cacti is an open source operational monitoring and fault management framework. A... Cacti is an open source operational monitoring and fault management framework. An authenticated SQL injection vulnerability was discovered which allows authenticated users to perform privilege escalation and remote code execution. The vulnerability resides in the `graphs.php` file. When dealing with the cases of ajax_hosts and ajax_hosts_noany, if the `site_id` parame
debian
CVE-2023-39362HIGHCVSS 7.2PoCfixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39362 [HIGH] CVE-2023-39362: cacti - Cacti is an open source operational monitoring and fault management framework. I... Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server. The `lib/snmp.php` file has a set of functions, with similar be
debian
CVE-2023-39357HIGHCVSS 8.8fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39357 [HIGH] CVE-2023-39357: cacti - Cacti is an open source operational monitoring and fault management framework. A... Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type is numeric, the sql_save function directly utilizes user input. Many files and functions calling the sql_save function do not perform prior validation of user input, leading to the existence of multiple SQL injection vul
debian
CVE-2023-49085HIGHCVSS 8.8PoCfixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2023
CVE-2023-49085 [HIGH] CVE-2023-49085: cacti - Cacti provides an operational monitoring and fault management framework. In vers... Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the `pollers.php`. Impact of the vulnerability - arbitrary SQL code execution. As of time of publi
debian
CVE-2023-39516MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39516 [MEDIUM] CVE-2023-39516: cacti - Cacti is an open source operational monitoring and fault management framework. A... Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-t
debian
CVE-2023-39514MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39514 [MEDIUM] CVE-2023-39514: cacti - Cacti is an open source operational monitoring and fault management framework. A... Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-t
debian
CVE-2023-50250MEDIUMCVSS 5.4fixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2023
CVE-2023-50250 [MEDIUM] CVE-2023-50250: cacti - Cacti is an open source operational monitoring and fault management framework. A... Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in version 1.2.25. Attackers can exploit this vulnerability to perform actions on behalf of other users. The vulnerability is found in `templates_import.php.` When uploading an xml template file, if the XML file does not pass
debian
CVE-2023-30534MEDIUMCVSS 4.3PoCfixed in cacti 1.2.25+ds1-1 (forky)2023
CVE-2023-30534 [MEDIUM] CVE-2023-30534: cacti - Cacti is an open source operational monitoring and fault management framework. T... Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadgets are not included, making them inaccessible and the insecure deserializations not exploitable. Each instance of ins
debian
CVE-2023-49088MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2023
CVE-2023-49088 [MEDIUM] CVE-2023-49088: cacti - Cacti is an open source operational monitoring and fault management framework. T... Cacti is an open source operational monitoring and fault management framework. The fix applied for CVE-2023-39515 in version 1.2.25 is incomplete as it enables an adversary to have a victim browser execute malicious code when a victim user hovers their mouse over the malicious data source path in `data_debug.php`. To perform the cross-site scripting attack, the adve
debian
CVE-2023-46490MEDIUMCVSS 6.5fixed in cacti 1.2.26+ds1-1 (forky)2023
CVE-2023-46490 [MEDIUM] CVE-2023-46490: cacti - SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain ... SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers.php function. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.2.26+ds1-1) sid: resolved (fixed in 1.2.26+ds1-1) trixie: resolved (fixed in 1.2.26+ds1-1)
debian