CVE-2022-48538: Medium severity cacti vulnerability
Published Aug 22, 2023
·Updated
In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cactildapauth() allows a zero as the password.
Affected Software
1 affected component
Cacti Cacti=1.2.19
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Cacti vulnerability?
The vulnerability ID for this Cacti vulnerability is CVE-2022-48538.
2
What is the severity of CVE-2022-48538?
The severity of CVE-2022-48538 is medium, with a severity value of 5.3.
3
How does the authentication bypass vulnerability in Cacti 1.2.19 work?
The authentication bypass in Cacti 1.2.19 occurs due to improper validation in the PHP code, specifically in cacti_ldap_auth(), which allows a zero as the password.
4
Which version of Cacti is affected by CVE-2022-48538?
CVE-2022-48538 affects Cacti version 1.2.19.
5
How can I fix the authentication bypass vulnerability in Cacti 1.2.19?
To fix the authentication bypass vulnerability in Cacti 1.2.19, you should update to a patched version recommended by the vendor.