CVE-2022-46169: Unauthenticated Command Injection
Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.
Other sources
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides in the remoteagent.php file. This file can be accessed without authentication. This function retrieves the IP address of the client via getclientaddr and resolves this IP address to the corresponding hostname via gethostbyaddr. After this, it is verified that an entry within the poller table exists, where the hostname corresponds to the resolved hostname. If such an entry was found, the function returns true and the client is authorized. This authorization can be bypassed due to the implementation of the getclientaddr function. The function is defined in the file lib/functions.php and checks serval $SERVER variables to determine the IP address of the client. The variables beginning with HTTP can be arbitrarily set by an attacker. Since there is a default entry in the poller table with the hostname of the server running Cacti, an attacker can bypass the authentication e.g. by providing the header Forwarded-For: <TARGETIP>. This way the function getclientaddr returns the IP address of the server running Cacti. The following call to gethostbyaddr will resolve this IP address to the hostname of the server, which will pass the poller hostname check because of the default entry. After the authorization of the remoteagent.php file is bypassed, an attacker can trigger different actions. One of these actions is called polldata. The called function pollfordata retrieves a few request parameters and loads the corresponding polleritem entries from the database. If the action of a polleritem equals POLLERACTIONSCRIPTPHP, the function procopen is used to execute a PHP script. The attacker-controlled parameter $pollerid is retrieved via the function getnfilterrequestvar, which allows arbitrary strings. This variable is later inserted into the string passed to procopen, which leads to a command injection vulnerability. By e.g. providing the pollerid=;id the id command is executed. In order to reach the vulnerable call, the attacker must provide a hostid and localdataid, where the action of the corresponding polleritem is set to POLLERACTIONSCRIPTPHP. Both of these ids (hostid and localdataid) can easily be bruteforced. The only requirement is that a polleritem with an POLLERACTIONSCRIPTPHP action exists. This is very likely on a productive instance because this action is added by some predefined templates like Device - Uptime or Device - Polling Time.
This command injection vulnerability allows an unauthenticated user to execute arbitrary commands if a polleritem with the action type POLLERACTIONSCRIPTPHP (2) is configured. The authorization bypass should be prevented by not allowing an attacker to make getclientaddr (file lib/functions.php) return an arbitrary IP address. This could be done by not honoring the HTTP... $SERVER variables. If these should be kept for compatibility reasons it should at least be prevented to fake the IP address of the server running Cacti. This vulnerability has been addressed in both the 1.2.x and 1.3.x release branches with 1.2.23 being the first release containing the patch.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/cactito a version that resolves this vulnerability.Fixed in 1.2.16+ds1-2+deb11u3Fixed in 1.2.16+ds1-2+deb11u4Fixed in 1.2.24+ds1-1+deb12u4Fixed in 1.2.24+ds1-1+deb12u2Fixed in 1.2.28+ds1-3 - Upgrade
Upgrade
Cactito a version that resolves this vulnerability.Fixed in 1.2.23 - Upgrade
Upgrade
debian/cactito a version that resolves this vulnerability.Fixed in 1.2.16+ds1-2+deb11u3 - Upgrade
Upgrade
debian/cactito a version that resolves this vulnerability.Fixed in 1.2.16+ds1-2+deb11u4 - Upgrade
Upgrade
debian/cactito a version that resolves this vulnerability.Fixed in 1.2.24+ds1-1+deb12u4 - Upgrade
Upgrade
debian/cactito a version that resolves this vulnerability.Fixed in 1.2.24+ds1-1+deb12u2 - Upgrade
Upgrade
debian/cactito a version that resolves this vulnerability.Fixed in 1.2.28+ds1-3 - Compensating control
Block or restrict access to remote_agent.php and ensure intermediary proxies/firewalls remove or ignore attacker-controlled HTTP_* headers (for example Forwarded-For) so that Cacti's get_client_addr cannot be forced to return an attacker-supplied IP address.
Event History
Frequently Asked Questions
What is CVE-2022-46169?
CVE-2022-46169 is a command injection vulnerability in Cacti.
How does CVE-2022-46169 affect Cacti?
CVE-2022-46169 allows an unauthenticated user to execute code on Cacti.
What is the severity of CVE-2022-46169?
The severity of CVE-2022-46169 is high.
How can I fix the CVE-2022-46169 vulnerability?
To fix the CVE-2022-46169 vulnerability, update Cacti to the latest version and apply any available patches.
Where can I find more information about CVE-2022-46169?
You can find more information about CVE-2022-46169 on the Cacti GitHub security advisories page.