CVE-2023-39362
Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server. The `lib/snmp.php` file has a set of functions, with similar behavior, that accept in input some variables and place them into an `exec` call without a proper escape or validation. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
- Cacti
- < 1.2.25
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 82.2% (100th percentile)
- Weakness
- CWE-77, CWE-78
- NVD status
- Modified
- Published
- 2023-09-05
CVE-2023-39362 at NVD
7 known exploits for CVE-2023-39362
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2023-39362-cacti-snmp-command-injection-poc
cacti-rce-snmp-options-vulnerable-application
Exploit for OS Command Injection in Cacti
Cacti 1.2.24 Command Injection
Cacti 1.2.24 - Authenticated command injection when using SNMP options Vulnerability
Cacti 1.2.24 - Authenticated command injection when using SNMP options
Exploit for OS Command Injection in Cacti