Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2025-66399

9 месяцев назад

Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configuration functionality. An authenticated Cacti user can supply crafted SNMP community strings containing control characters (including newlines) that are accepted, stored verbatim in the database, and later embedded into backend SNMP operations. In environments where downstream SNMP tooling or wrappers interpret newline-separated tokens as command boundaries, this can lead to unintended command execution with the privileges of the Cacti process. This vulnerability is fixed in 1.2.29.

CVSS3: 8.8
EPSS: Средний
nvd логотип

CVE-2025-66399

9 месяцев назад

Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configuration functionality. An authenticated Cacti user can supply crafted SNMP community strings containing control characters (including newlines) that are accepted, stored verbatim in the database, and later embedded into backend SNMP operations. In environments where downstream SNMP tooling or wrappers interpret newline-separated tokens as command boundaries, this can lead to unintended command execution with the privileges of the Cacti process. This vulnerability is fixed in 1.2.29.

CVSS3: 8.8
EPSS: Средний
debian логотип

CVE-2025-66399

9 месяцев назад

Cacti is an open source performance and fault management framework. Pr ...

CVSS3: 8.8
EPSS: Средний
fstec логотип

BDU:2025-15397

9 месяцев назад

Уязвимость функции настройки SNMP-устройств программного средства мониторинга сети Cacti, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Средний
redos логотип

ROS-20260401-80-0036

5 месяцев назад

Уязвимость cacti

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-66399

Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configuration functionality. An authenticated Cacti user can supply crafted SNMP community strings containing control characters (including newlines) that are accepted, stored verbatim in the database, and later embedded into backend SNMP operations. In environments where downstream SNMP tooling or wrappers interpret newline-separated tokens as command boundaries, this can lead to unintended command execution with the privileges of the Cacti process. This vulnerability is fixed in 1.2.29.

CVSS3: 8.8
11%
Средний
9 месяцев назад
nvd логотип
CVE-2025-66399

Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configuration functionality. An authenticated Cacti user can supply crafted SNMP community strings containing control characters (including newlines) that are accepted, stored verbatim in the database, and later embedded into backend SNMP operations. In environments where downstream SNMP tooling or wrappers interpret newline-separated tokens as command boundaries, this can lead to unintended command execution with the privileges of the Cacti process. This vulnerability is fixed in 1.2.29.

CVSS3: 8.8
11%
Средний
9 месяцев назад
debian логотип
CVE-2025-66399

Cacti is an open source performance and fault management framework. Pr ...

CVSS3: 8.8
11%
Средний
9 месяцев назад
fstec логотип
BDU:2025-15397

Уязвимость функции настройки SNMP-устройств программного средства мониторинга сети Cacti, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
11%
Средний
9 месяцев назад
redos логотип
ROS-20260401-80-0036

Уязвимость cacti

CVSS3: 8.8
11%
Средний
5 месяцев назад

Уязвимостей на страницу