USN-7226-1: Cacti vulnerability
Published Jan 23, 2025
·Updated
It was discovered that Cacti did not properly sanitize the 'pollerid' parameter in the "remoteagent.php" file. A remote attacker could possibly use this issue to achieve remote code execution.
Affected Software
6 affected componentsFixes available
All of the following
ubuntu/cacti<1.2.19+ds1-2ubuntu1.1+esm2
1.2.19+ds1-2ubuntu1.1+esm2
Ubuntu Ubuntu=22.04
All of the following
ubuntu/cacti<1.2.10+ds1-1ubuntu1.1+esm2
1.2.10+ds1-1ubuntu1.1+esm2
Ubuntu Ubuntu=20.04
All of the following
ubuntu/cacti<1.1.38+ds1-1ubuntu0.1~esm4
1.1.38+ds1-1ubuntu0.1~esm4
Ubuntu Ubuntu=18.04
Event History
Jan 23, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7226-1?
USN-7226-1 has a high severity due to the potential for remote code execution.
2
How do I fix USN-7226-1?
To fix USN-7226-1, you should upgrade to the fixed versions of Cacti for your Ubuntu release.
3
What versions of Cacti are affected by USN-7226-1?
USN-7226-1 affects specific versions of Cacti across Ubuntu 18.04, 20.04, and 22.04.
4
What is the root cause of USN-7226-1?
USN-7226-1 is caused by improper sanitization of the 'poller_id' parameter in Cacti's remote_agent.php file.
5
Can USN-7226-1 be exploited by an unauthenticated user?
Yes, a remote attacker can exploit USN-7226-1 to achieve remote code execution without authentication.