CVE-2022-0730: Critical severity cacti vulnerability
Published Mar 3, 2022
·Updated
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
Affected Software
8 affected componentsFixes available
debian/cacti<=1.2.2+ds1-2+deb10u4
1.2.2+ds1-2+deb10u51.2.16+ds1-2+deb11u11.2.24+ds1-11.2.25+ds1-2
Cacti Cacti=1.2.19
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Event History
Mar 3, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Mar 30, 2022
Data Sourced
07:18 PM
SeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-0730?
CVE-2022-0730 is a vulnerability in Cacti that allows bypassing authentication under certain LDAP conditions.
2
How does CVE-2022-0730 affect Cacti?
CVE-2022-0730 affects Cacti version 1.2.19.
3
How does CVE-2022-0730 affect Debian Linux?
CVE-2022-0730 affects Debian Linux versions 9.0, 10.0, and 11.0.
4
What is the severity of CVE-2022-0730?
CVE-2022-0730 has a severity rating of critical (9.8).
5
How do I fix CVE-2022-0730 in Cacti?
To fix CVE-2022-0730 in Cacti, update to version 1.2.25+ds1-2 or a later version.
6
How do I fix CVE-2022-0730 in Debian Linux?
To fix CVE-2022-0730 in Debian Linux, apply the appropriate updates: 1.2.2+ds1-2+deb10u5, 1.2.16+ds1-2+deb11u1, 1.2.24+ds1-1, or 1.2.25+ds1-2.
7
What is the CWE classification of CVE-2022-0730?
CVE-2022-0730 is classified as CWE-287.