CVE-2023-37543: High severity cacti vulnerability
Published Aug 10, 2023
·Updated
Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified localgraphid parameter to graphxport.php. This is a different vulnerability than CVE-2019-16723.
Affected Software
1 affected component
Cacti Cacti<1.2.6
Event History
Aug 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-37543?
The severity of CVE-2023-37543 is high with a CVSS score of 7.5.
2
What is CVE-2023-37543 about?
CVE-2023-37543 is an IDOR (Insecure Direct Object Reference) vulnerability in Cacti before version 1.2.6 that allows unauthorized access to any graph.
3
How can an attacker exploit CVE-2023-37543?
An attacker can exploit CVE-2023-37543 by modifying the local_graph_id parameter in graph_xport.php to access any graph.
4
Is CVE-2023-37543 different from CVE-2019-16723?
Yes, CVE-2023-37543 is a different vulnerability than CVE-2019-16723.
5
How can I fix CVE-2023-37543?
To fix CVE-2023-37543, upgrade to Cacti version 1.2.6 or later.