• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
critical flaws in cacti framework could let attackers execute malicious

Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious Code

You are here: Home / General Cyber Security News / Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious Code
May 14, 2024

The maintainers of the Cacti open up-source network monitoring and fault management framework have dealt with a dozen security flaws, together with two critical issues that could direct to the execution of arbitrary code.

The most severe of the vulnerabilities are outlined below –

  • CVE-2024-25641 (CVSS rating: 9.1) – An arbitrary file generate vulnerability in the “Bundle Import” aspect that enables authenticated people owning the “Import Templates” authorization to execute arbitrary PHP code on the web server, ensuing in distant code execution
  • CVE-2024-29895 (CVSS rating: 10.) – A command injection vulnerability enables any unauthenticated person to execute arbitrary command on the server when the “sign up_argc_argv” option of PHP is On

Cacti Framework

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Also tackled by Cacti are two other high-severity flaws that could lead to code execution by way of SQL injection and file inclusion –

  • CVE-2024-31445 (CVSS score: 8.8) – An SQL injection vulnerability in api_automation.php that permits authenticated consumers to carry out privilege escalation and remote code execution
  • CVE-2024-31459 (CVSS score: N/A) – A file inclusion issue in the “lib/plugin.php” file that could be combined with SQL injection vulnerabilities to final result in remote code execution

It truly is value noting that 10 out of the 12 flaws, with the exception of CVE-2024-29895 and CVE-2024-30268 (CVSS rating: 6.1), affect all variations of Cacti, like and prior to 1.2.26. They have been addressed in variation 1.2.27 introduced on May possibly 13, 2024. The two other flaws have an affect on the growth variations 1.3.x.

Cybersecurity

The improvement comes more than eight months just after the disclosure of a further critical SQL injection vulnerability (CVE-2023-39361, CVSS score: 9.8) that could permit an attacker to get hold of elevated permissions and execute destructive code.

In early 2023, a 3rd critical flaw tracked as CVE-2022-46169 (CVSS score: 9.8) arrived underneath lively exploitation in the wild, allowing menace actors to breach internet-exposed Cacti servers to provide botnet malware these types of as MooBot and ShellBot.

With evidence-of-strategy (PoC) exploits publicly accessible for these shortcomings (in the respective GitHub advisories), it is suggested that people get actions to update their occasions to the hottest variation as shortly as possible to mitigate opportunity threats.

Discovered this short article fascinating? Follow us on Twitter  and LinkedIn to examine a lot more distinctive content we post.


Some sections of this write-up are sourced from:
thehackernews.com

Previous Post: «6 mistakes organizations make when deploying advanced authentication 6 Mistakes Organizations Make When Deploying Advanced Authentication
Next Post: New Chrome Zero-Day Vulnerability CVE-2024-4761 Under Active Exploitation new chrome zero day vulnerability cve 2024 4761 under active exploitation»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.