9.8
CVSSv3

CVE-2022-0730

Published: 03/03/2022 Updated: 12/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cacti cacti 1.2.19

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

fedoraproject fedora 34

fedoraproject fedora 35

fedoraproject fedora 36

Vendor Advisories

Debian Bug report logs - #1008693 cacti: CVE-2022-0730 Package: src:cacti; Maintainer for src:cacti is Cacti Maintainer <pkg-cacti-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 30 Mar 2022 19:18:02 UTC Severity: important Tags: security, upstream Found in version ca ...
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types (CVE-2022-0730) ...
Two security vulnerabilities have been discovered in Cacti, a web interface for graphing of monitoring systems, which could result in unauthenticated command injection or LDAP authentication bypass For the stable distribution (bullseye), these problems have been fixed in version 1216+ds1-2+deb11u1 We recommend that you upgrade your cacti packag ...

Github Repositories

CVE-2022-0730 Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types authentication complexity vector NONE MEDIUM NETWORK confidentiality integrity availability PARTIAL PARTIAL PARTIAL CVSS Score: 68 References Cacti/cacti#4562 listsdebianorg/debian-lts-announce/2022/03/msg00038html lists