漏洞描述
Cacti v1.2.8 is susceptible to remote code execution. This vulnerability could be exploited without authentication if "Guest Realtime Graphs" privileges are enabled.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
shells.systemshttps://shells.systems/cacti-v1-2-8-authenticated-remote-code-execution-cve-2020-8813/↗github.comhttps://github.com/Cacti/cacti/releases↗gist.github.comhttps://gist.github.com/mhaskar/ebe6b74c32fd0f7e1eedf1aabfd44129↗drive.google.comhttps://drive.google.com/file/d/1A8hxTyk_NgSp04zPX-23nPbsSDeyDFio/view↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2020-8813↗