HIGH

CVE-2023-39362

CVSS v3

7.2

HIGH

EPSS Score

86.7%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server. The `lib/snmp.php` file has a set of functions, with similar behavior, that accept in input some variables and place them into an `exec` call without a proper escape or validation. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Technical details

Published
9/5/2023
Exploit-DB
EDB-51740

Frequently asked questions

What is CVE-2023-39362?

Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server. The `lib/snmp.php` file has a set of functions, with similar behavior, that accept in input some variables and place them into an `exec` call without a proper escape or validation. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Is CVE-2023-39362 actively exploited?

Active exploitation of CVE-2023-39362 has not been confirmed. The EPSS score is 86.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-39362?

CVE-2023-39362 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2023-39362 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.