CVE-2022-46169 is a critical command injection vulnerability in Cacti, an open-source monitoring platform, affecting versions prior to 1.2.23. An unauthenticated attacker can execute arbitrary code on a Cacti server if a specific data source is configured, by bypassing authentication through manipulated HTTP headers and exploiting a flaw in the remote_agent.php file. This vulnerability has a CVSS score of 9.8 (CRITICAL), indicating a network-based attack with low complexity and no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. The EPSS score of 0.94469 and FAUCET Risk Score of 100/100 highlight its extreme exploitability and impact. CVE-2022-46169 is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog and numerous media reports. Publicly available exploit modules exist for Metasploit and Nuclei, and it has garnered significant community discussion with over 20 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.23CPE matchmatch criteria | cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.