CRITICAL

CVE-2023-39361

CVSS v3

9.8

CRITICAL

EPSS Score

92.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Technical details

Published
9/5/2023

Frequently asked questions

What is CVE-2023-39361?

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Is CVE-2023-39361 actively exploited?

Active exploitation of CVE-2023-39361 has not been confirmed. The EPSS score is 92.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-39361?

CVE-2023-39361 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-39361 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.