CVE-2022-46169
Cacti
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides in the `remote_agent.php` file. This file can be accessed without authentication. This function retrieves the IP address of the client via `get_client_addr` and resolves this IP address to the corresponding hostname via `gethostby...
- CVSS
- 9.8
- EPSS
- 99.8% 100.0% percentile
- CISA KEV
- Listed
- Published
- 2022.12.06