Threat Advisory

Hackers exploit Cacti critical bug to install malware, open reverse shells

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

A serious security flaw that hackers have already started to exploit, affects more than 1,600 installations of the Cacti device monitoring tool that are accessible through the internet. Cacti is an operational and fault management monitoring solution for network devices that also provides graphical visualization. The vulnerability tracked as CVE-2022-46169 is a command injection vulnerability that allows an unauthenticated user to execute arbitrary code on a server running cacti. This exploit can install a botnet and open a reverse shell on the host to run port scans.[/subscribe_to_unlock_form]

Summary:

A serious security flaw that hackers have already started to exploit, affects more than 1,600 installations of the Cacti device monitoring tool that are accessible through the internet. Cacti is an operational and fault management monitoring solution for network devices that also provides graphical visualization. The vulnerability tracked as CVE-2022-46169 is a command injection vulnerability that allows an unauthenticated user to execute arbitrary code on a server running cacti. This exploit can install a botnet and open a reverse shell on the host to run port scans.[emaillocker id="1283"]

Recommendation:

We strongly recommend updating the vulnerable software to the latest versions: 1.2.x, and 1.3.x. It can be found on below link –

Cacti® - The Complete RRDTool-based Graphing Solution

References:

The following reports contain further technical details:

Cacti: Unauthenticated Remote Code Execution | Sonar (sonarsource.com)

[/emaillocker]
crossmenu