Executive brief
Cacti contains a command injection vulnerability in remote_agent.php due to improper authorization bypass and insufficient sanitization of the poller_id parameter. An unauthenticated attacker can bypass IP-based authentication by spoofing HTTP headers and execute arbitrary OS commands via the poll_for_data function when a script-based poller item is configured.
Affected products
- Cacti Cacti 1.2.x before 1.2.23, 1.3.x before 1.3.0
Timeline
- 2022-12-05: disclosed: Date based on GHSA-6p93-p743-35gf advisory publication
- 2023-02-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-02-16: exploited: Confirmed exploited in the wild per CISA KEV catalog entry