CVE-2022-46169
Cacti: Command Injection
As of , CVE-2022-46169 in Cacti is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 16 February 2023
- US federal deadline
- 9 March 202321 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.84 on 16 February 2023EPSS on the day CISA listed it.
- Public exploit
- 1 Metasploit module and 1 Exploit-DB entry
- Fix
- Vendor advice: github.comLinks below, from CISA's entry.
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.
CISA's description
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides in the `remote_agent.php` file. This file can be accessed without authentication. This function retrieves the IP address of the client via `get_client_addr` and resolves this IP address to the corresponding hostname via `gethostbyaddr`. After this, it is verified that an entry within the `poller` table exists, where the hostname corresponds to the resolved hostname. If such an entry was found, the function returns `true` and the client is authorized. This authorization can be bypassed due to the implementation of the `get_client_addr` function. The function is defined in the file `lib/functions.php` and checks serval `$_SERVER` variables to determine the IP address of the client. The variables beginning with `HTTP_` can be arbitrarily set by an attacker. Since there is a default entry in the `poller` table with the hostname of the server running Cacti, an attacker can bypass the authentication e.g. by providing the header `Forwarded-For: <TARGETIP>`. This way the function `get_client_addr` returns the IP address of the server running Cacti.
The CVE record's description, from GitHub_M, shortened; full text on cve.org
- CVE published
- 5 December 2022
- Assigned by
- GitHub_M
- CVSS
- 9.8 Critical (CVSS 3.1, from the CNA)
- CWE-74
- Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
- Exploit-DB published an exploit (EDB-ID 51166).
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: Cacti 1.2.22 unauthenticated command injectionexploit module, rank excellent
- Exploit-DB: Cacti v1.2.22 - Remote Command Execution (RCE)EDB-ID 51166, 31 March 2023
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org