CVE-2020-7058: Input Validation
Published Jan 15, 2020
·Updated
DISPUTED datainput.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. NOTE: the vendor has stated "This is a false alarm."
Affected Software
1 affected component
Cacti Cacti=1.2.8
Event History
Jan 15, 2020
CVE Published
via MITRE·06:03 AM
Data Sourced
via MITRE·06:03 AM
Description
Disputed
07:15 AM
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-7058?
CVE-2020-7058 is a vulnerability in Cacti 1.2.8 that allows remote code execution.
2
How can this vulnerability be exploited?
This vulnerability can be exploited by sending a crafted Input String to the Data Collection -> Data Input Methods -> Unix -> Ping Host feature in Cacti 1.2.8.
3
What is the severity of CVE-2020-7058?
The severity of CVE-2020-7058 is high with a CVSS score of 8.8.
4
Is there a fix available for CVE-2020-7058?
The vendor has disputed the vulnerability and stated that it is a false alarm.
5
Where can I find more information about CVE-2020-7058?
You can find more information about CVE-2020-7058 in the GitHub issue: https://github.com/Cacti/cacti/issues/3186.