CVE-2016-2313: High severity cacti vulnerability
Published Apr 13, 2016
·Updated
authlogin.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
Affected Software
4 affected components
Cacti Cacti<=0.8.8f
openSUSE Leap=42.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Event History
Apr 13, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2313?
CVE-2016-2313 has a medium severity rating due to its potential for unauthorized access.
2
How do I fix CVE-2016-2313?
To fix CVE-2016-2313, upgrade Cacti to version 0.8.8g or later.
3
Who is affected by CVE-2016-2313?
CVE-2016-2313 affects remote authenticated users of Cacti versions prior to 0.8.8g.
4
What type of vulnerability is CVE-2016-2313?
CVE-2016-2313 is an access control vulnerability that allows unauthorized actions.
5
Can CVE-2016-2313 be exploited remotely?
Yes, CVE-2016-2313 can be exploited remotely by authenticated users.