
Proof-of-concept-Exploit für authentifizierte OS-Befehlsinjektion (CWE-78) in Cacti ≤1.2.30, die Remote-Codeausführung mit CVSS 7.2 erreicht.
| Feld | Wert |
|---|
| Produkt | Cacti — Vollständige RRDtool-basierte Graphing-Lösung |
| Betroffene Version(en) | ≤ 1.2.30 |
| Schwachstellentyp | OS-Befehlsinjektion (CWE-78) |
| Angriffsvektor | Netzwerk (authentifizierter Administrator) |
| Authentifizierung | Ja — Administratorkonto erforderlich |
| Ziel-Betriebssystem | Windows (beide Vektoren) + Linux (direkter input_string-Vektor) |
| CVSSv3.1-Score | 7.2 HOCH |
| Vektor | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
[02] Referenz