CVE-2024-43363 is a critical Remote Code Execution (RCE) vulnerability affecting Cacti, an open-source performance and fault management framework. An authenticated administrator can inject malicious PHP code into a device's hostname, which is then written to the Cacti log file through a specific installation process step. Accessing the poisoned log file URL subsequently executes the injected code, leading to RCE. This vulnerability carries a CVSS score of 7.2 (High), indicating a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. The prerequisite of administrator credentials mitigates some risk, but the potential for complete system compromise is significant. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or community discussion has been identified. Despite the lack of immediate exploitation, the high FAUCET Risk Score of 98/100 and the vulnerability's presence in the Cacti product warrant immediate attention. Users are strongly advised to upgrade to Cacti version 1.2.28 or later, as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.28CPE matchmatch criteria | cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.