First published: Tue Aug 22 2023(Updated: )
In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti Cacti | =1.2.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Cacti vulnerability is CVE-2022-48538.
The severity of CVE-2022-48538 is medium, with a severity value of 5.3.
The authentication bypass in Cacti 1.2.19 occurs due to improper validation in the PHP code, specifically in cacti_ldap_auth(), which allows a zero as the password.
CVE-2022-48538 affects Cacti version 1.2.19.
To fix the authentication bypass vulnerability in Cacti 1.2.19, you should update to a patched version recommended by the vendor.