Alert!

Monitoring software: Cacti vulnerabilities allow malicious code to be injected

An updated version of the Cacti monitoring software closes several security gaps, some of which are critical. This allows attackers to smuggle in code.

Save to Pocket listen Print view
Stilisiertes Bild: Laptop steht auf Schreibtisch vor Serverschränken, es brennt

Security gaps jeopardize network security.

(Image: Bild erstellt mit KI in Bing Designer durch heise online / dmk)

2 min. read
This article was originally published in German and has been automatically translated.

The new version 1.2.27 of the monitoring software Cacti closes several security vulnerabilities, among other things. The severity level ranges up to "critical" and allows attackers to inject malicious code or cause damage with SQL injections, for example.

The changelog lists nine changes in Cacti as security patches. Registered users with authorization to import templates can inject arbitrary malicious code due to a vulnerability that allows the writing of arbitrary files in the package import function (CVE-2024-25641, CVSS 9.1, risk"critical").

Authenticated attackers can also abuse an SQL injection vulnerability in api_automation.php in the automation_get_new_graphs_sql function to escalate their privileges or inject and execute malicious code (CVE-2024-31445, CVSS 8.8, high). A problem with including files in lib/plugin.php can be combined with SQL injection vulnerabilities to smuggle in arbitrary code (CVE-2024-31459, no CVSS value, high).

The developers classify the other vulnerabilities as medium risk. The following vulnerabilities, sorted in descending order of severity, are closed by the new Cacti version:

As some of the vulnerabilities are considered critical or high-risk, IT managers should update their Cacti systems to the new version as soon as possible. The updated version can be downloaded from the Cacti download page.

The developers last patched security leaks in Cacti in January. These high-risk vulnerabilities also allowed SQL injections or the injection of arbitrary PHP code.

(dmk)