CVE-2024-43363

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Oct 7, 2024
Updated: Oct 17, 2024
CWE ID 94

Summary

CVE-2024-43363 affects the open source Cacti performance and fault management framework. Malicious administrators can exploit this vulnerability by creating a device with a hostname containing malicious PHP code during the installation process, specifically during step 5. The malicious hostname, once logged, allows attackers to execute remote commands through the Cacti log file URL. This vulnerability, which has been addressed in version 1.2.28, is significant due to the potential for remote code execution (RCE). It is strongly recommended that users upgrade to the latest version to mitigate this risk, as there are currently no known workarounds.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share