Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious Code
ID: aed7e086-1a57-5e5f-82d0-3816569077c9
STIX ID: report--aed7e086-1a57-5e5f-82d0-3816569077c9
Feed Name: The Hacker News
Threat Score
Cacti maintainers released version 1.2.27 (May 13, 2024) addressing a dozen vulnerabilities — including critical RCEs (CVE-2024-25641, CVE-2024-29895), a high-severity SQL injection (CVE-2024-31445), and a file-inclusion issue (CVE-2024-31459) — many of which affect all supported versions; proof-of-concept exploits are available and prior Cacti flaws have been actively exploited to deliver botnet malware, so users are advised to update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
