CVE-2019-17358

CVSS v3.1 8.1 (High)
81% Progress
CVSS v2.0 5.5 (Medium)
55% Progress
EPSS 0.74 % (81th)
0.74% Progress
Affected Products 3
Advisories 15

Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module.

Weaknesses
CWE-502
Deserialization of Untrusted Data
CWE-787
Out-of-bounds Write
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2019-12-12 14:15:16
(4 years ago)
Updated Date
2020-08-24 17:37:01
(4 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Cacti 1.2.7 and prior versions cpe:2.3:a:cacti:cacti <= 1.2.7

Configuration #2

    CPE23 From Up To
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0

Configuration #3

    CPE23 From Up To
  Opensuse Leap 42.3 cpe:2.3:o:opensuse:leap:42.3
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...