CVE-2014-2328: Medium severity Cacti Cacti vulnerability
lib/graphexport.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/cactito a version that resolves this vulnerability.Fixed in 1.2.16+ds1-2+deb11u3Fixed in 1.2.16+ds1-2+deb11u5Fixed in 1.2.24+ds1-1+deb12u5Fixed in 1.2.30+ds1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2328?
CVE-2014-2328 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2014-2328?
To mitigate CVE-2014-2328, upgrade to Cacti versions 1.2.16+ds1-2+deb11u3, 1.2.24+ds1-1+deb12u2, or 1.2.27+ds1-2.
Which versions of Cacti are affected by CVE-2014-2328?
CVE-2014-2328 affects Cacti versions 0.8.7g, 0.8.8b, and earlier.
Can CVE-2014-2328 be exploited by unauthenticated users?
No, CVE-2014-2328 requires remote authenticated users to exploit the vulnerability.
What are the potential impacts of CVE-2014-2328?
Exploitation of CVE-2014-2328 can lead to arbitrary command execution on the server hosting Cacti.