Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-31132

Опубликовано: 05 сент. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 7.8

Описание

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary PHP files in a web document directory. The user can then execute the PHP files under the security context of SYSTEM. This allows an attacker to escalate privilege from a normal user account to SYSTEM. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

esm-apps/bionic

not-affected

esm-apps/focal

not-affected

esm-apps/jammy

not-affected

esm-apps/xenial

not-affected

esm-infra-legacy/trusty

not-affected

focal

not-affected

jammy

not-affected

lunar

not-affected

Показывать по

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
больше 2 лет назад

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary PHP files in a web document directory. The user can then execute the PHP files under the security context of SYSTEM. This allows an attacker to escalate privilege from a normal user account to SYSTEM. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7.8
debian
больше 2 лет назад

Cacti is an open source operational monitoring and fault management fr ...

CVSS3: 7.8
fstec
больше 2 лет назад

Уязвимость программного средства мониторинга сети Cacti , связанная с отсутствием аутентификации для критичной функции, позволяющая нарушителю повысить свои привилегии

7.8 High

CVSS3

Уязвимость CVE-2023-31132