CVE-2022-46169: Unauthenticated Command Injection

Published Dec 5, 2022
·
Updated

Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.

Other sources

Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides in the remoteagent.php file. This file can be accessed without authentication. This function retrieves the IP address of the client via getclientaddr and resolves this IP address to the corresponding hostname via gethostbyaddr. After this, it is verified that an entry within the poller table exists, where the hostname corresponds to the resolved hostname. If such an entry was found, the function returns true and the client is authorized. This authorization can be bypassed due to the implementation of the getclientaddr function. The function is defined in the file lib/functions.php and checks serval $SERVER variables to determine the IP address of the client. The variables beginning with HTTP can be arbitrarily set by an attacker. Since there is a default entry in the poller table with the hostname of the server running Cacti, an attacker can bypass the authentication e.g. by providing the header Forwarded-For: <TARGETIP>. This way the function getclientaddr returns the IP address of the server running Cacti. The following call to gethostbyaddr will resolve this IP address to the hostname of the server, which will pass the poller hostname check because of the default entry. After the authorization of the remoteagent.php file is bypassed, an attacker can trigger different actions. One of these actions is called polldata. The called function pollfordata retrieves a few request parameters and loads the corresponding polleritem entries from the database. If the action of a polleritem equals POLLERACTIONSCRIPTPHP, the function procopen is used to execute a PHP script. The attacker-controlled parameter $pollerid is retrieved via the function getnfilterrequestvar, which allows arbitrary strings. This variable is later inserted into the string passed to procopen, which leads to a command injection vulnerability. By e.g. providing the pollerid=;id the id command is executed. In order to reach the vulnerable call, the attacker must provide a hostid and localdataid, where the action of the corresponding polleritem is set to POLLERACTIONSCRIPTPHP. Both of these ids (hostid and localdataid) can easily be bruteforced. The only requirement is that a polleritem with an POLLERACTIONSCRIPTPHP action exists. This is very likely on a productive instance because this action is added by some predefined templates like Device - Uptime or Device - Polling Time.

This command injection vulnerability allows an unauthenticated user to execute arbitrary commands if a polleritem with the action type POLLERACTIONSCRIPTPHP (2) is configured. The authorization bypass should be prevented by not allowing an attacker to make getclientaddr (file lib/functions.php) return an arbitrary IP address. This could be done by not honoring the HTTP... $SERVER variables. If these should be kept for compatibility reasons it should at least be prevented to fake the IP address of the server running Cacti. This vulnerability has been addressed in both the 1.2.x and 1.3.x release branches with 1.2.23 being the first release containing the patch.

MITRE

Affected Software

4 affected componentsFixes available
debian/cacti
1.2.16+ds1-2+deb11u31.2.16+ds1-2+deb11u41.2.24+ds1-1+deb12u41.2.24+ds1-1+deb12u21.2.28+ds1-3
Cacti Cacti<=1.2.22
Cacti Cacti
Cacti Cacti<1.2.23

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/cacti to a version that resolves this vulnerability.

    Fixed in 1.2.16+ds1-2+deb11u3Fixed in 1.2.16+ds1-2+deb11u4Fixed in 1.2.24+ds1-1+deb12u4Fixed in 1.2.24+ds1-1+deb12u2Fixed in 1.2.28+ds1-3
  2. Upgrade

    Upgrade Cacti to a version that resolves this vulnerability.

    Fixed in 1.2.23
  3. Upgrade

    Upgrade debian/cacti to a version that resolves this vulnerability.

    Fixed in 1.2.16+ds1-2+deb11u3
  4. Upgrade

    Upgrade debian/cacti to a version that resolves this vulnerability.

    Fixed in 1.2.16+ds1-2+deb11u4
  5. Upgrade

    Upgrade debian/cacti to a version that resolves this vulnerability.

    Fixed in 1.2.24+ds1-1+deb12u4
  6. Upgrade

    Upgrade debian/cacti to a version that resolves this vulnerability.

    Fixed in 1.2.24+ds1-1+deb12u2
  7. Upgrade

    Upgrade debian/cacti to a version that resolves this vulnerability.

    Fixed in 1.2.28+ds1-3
  8. Compensating control

    Block or restrict access to remote_agent.php and ensure intermediary proxies/firewalls remove or ignore attacker-controlled HTTP_* headers (for example Forwarded-For) so that Cacti's get_client_addr cannot be forced to return an attacker-supplied IP address.

Event History

Dec 5, 2022
CVE Published
via MITRE·08:48 PM
Data Sourced
via MITRE·08:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 6, 2022
Data Sourced
08:39 PM
SeverityAffected Software
Feb 16, 2023
Known Exploited
via CISA·12:00 AM
Jan 23, 2025
Data Sourced
via Launchpad·02:42 PM
Description
Jan 27, 2025
Data Sourced
via Ubuntu·02:41 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-46169?

CVE-2022-46169 is a command injection vulnerability in Cacti.

2

How does CVE-2022-46169 affect Cacti?

CVE-2022-46169 allows an unauthenticated user to execute code on Cacti.

3

What is the severity of CVE-2022-46169?

The severity of CVE-2022-46169 is high.

4

How can I fix the CVE-2022-46169 vulnerability?

To fix the CVE-2022-46169 vulnerability, update Cacti to the latest version and apply any available patches.

5

Where can I find more information about CVE-2022-46169?

You can find more information about CVE-2022-46169 on the Cacti GitHub security advisories page.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203