605
VMScore

CVE-2022-0730

Published: 03/03/2022 Updated: 12/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cacti cacti 1.2.19

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

fedoraproject fedora 34

fedoraproject fedora 35

fedoraproject fedora 36

Vendor Advisories

Debian Bug report logs - #1008693 cacti: CVE-2022-0730 Package: src:cacti; Maintainer for src:cacti is Cacti Maintainer <pkg-cacti-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 30 Mar 2022 19:18:02 UTC Severity: important Tags: security, upstream Found in version ca ...
Two security vulnerabilities have been discovered in Cacti, a web interface for graphing of monitoring systems, which could result in unauthenticated command injection or LDAP authentication bypass For the stable distribution (bullseye), these problems have been fixed in version 1216+ds1-2+deb11u1 We recommend that you upgrade your cacti packag ...
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types (CVE-2022-0730) ...