Cacti Alert
2164Warning Date
Severity Level
Warning Number
Target Sector
6 September, 2023
● Critical
2023-5775
All
Description:
Cacti has released security updates to address multiple vulnerabilities in the following product:
- Cacti
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- SQL injection
- Elevate user privileges
- Command Injection
Best practice and Recommendations:
The CERT team encourages users to review Cacti security advisory and update the affected product:
- https://github.com/Cacti/cacti/security/advisories/GHSA-6r43-q2fw-5wrg
- https://github.com/Cacti/cacti/security/advisories/GHSA-6jhp-mgqg-fhqg
- https://github.com/Cacti/cacti/security/advisories/GHSA-gj95-7xr8-9p7g
- https://github.com/Cacti/cacti/security/advisories/GHSA-q4wh-3f9w-836h
- https://github.com/Cacti/cacti/security/advisories/GHSA-g6ff-58cj-x3cp
- https://github.com/Cacti/cacti/security/advisories/GHSA-rf5w-pq3f-9876