CVE-2016-10700 is a high-severity authentication bypass vulnerability affecting Cacti versions prior to 1.0.0. It allows remote authenticated users leveraging web authentication to bypass intended access restrictions by logging in as a non-existent Cacti user, due to an oversight in handling the guest user. With a CVSS score of 8.8, this vulnerability presents a low-complexity attack vector that could lead to high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the vulnerability's ease of exploitation and potential impact warrant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0CPE matchmatch criteria | cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.