CVE-2023-31132
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Sep 5, 2023
Updated: Nov 3, 2023
CWE ID 306
Summary
CVE-2023-31132 is a privilege escalation vulnerability affecting versions of Cacti, an open source operational monitoring framework. A low-privileged OS user with access to a Windows host running Cacti can create and execute arbitrary PHP files in the web document directory, gaining SYSTEM-level privileges. Unaffected versions are 1.2.25 and above. Users are strongly advised to upgrade as soon as possible, as there are currently no known workarounds for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Cacti
- Cacti Cacti
Affected Vendors
- Cacti