Home / Companies / Sonar / Blog / Post Details
Content Deep Dive

Cacti: Unauthenticated Remote Code Execution

Blog post from Sonar

Post Details
Company
Date Published
Author
Stefan Schiller
Word Count
1,450
Company Posts That Month
6
Language
English
Hacker News Points
-
Post removed?
No
Summary

A critical command injection vulnerability was discovered in the Cacti IT monitoring solution, allowing unauthenticated attackers to run arbitrary commands under the same user as the web server process is running. The vulnerability affects Cacti version 1.2.22 and below and has a CVSS score of 9.8. An authentication bypass vulnerability was also found, which allows attackers to access remote_agent.php without authorization. Both vulnerabilities were mitigated with patches that ensure proper validation and escaping of user input. The discovery highlights the importance of security on all layers and emphasizes the need for security considerations to be integrated into development practices.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 2 1,710 362 136 +47%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.