CVE-2014-2709: High severity Cacti Cacti vulnerability
lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/cactito a version that resolves this vulnerability.Fixed in 1.2.16+ds1-2+deb11u3Fixed in 1.2.16+ds1-2+deb11u5Fixed in 1.2.24+ds1-1+deb12u5Fixed in 1.2.30+ds1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2709?
CVE-2014-2709 is considered a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2014-2709?
To fix CVE-2014-2709, upgrade to Cacti version 0.8.8c or later, or apply available patches that address the vulnerability.
What versions of Cacti are affected by CVE-2014-2709?
CVE-2014-2709 affects Cacti versions 0.8.7g, 0.8.8b, and earlier.
Can CVE-2014-2709 affect my Debian system?
Yes, CVE-2014-2709 can affect Debian systems running vulnerable versions of Cacti such as those prior to 0.8.8c.
Is CVE-2014-2709 exploitable remotely?
Yes, CVE-2014-2709 can be exploited remotely by attackers who manipulate input parameters.