CVE-2019-16723
Advisory lineage Upstream: 0 Downstream: 7
Modified
Published: 23 Sept 2019, 14:24
Last modified:05 Aug 2024, 01:24
Vulnerability Summary
Overall Risk (default)
low
17/100 CVSS Score
4.3 MEDIUM
v3.1 (nvd)
EPSS Score
0.27% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
23 Sept 2019, 14:24
Published
Vulnerability first disclosed
05 Aug 2024, 01:24
Last Modified
Vulnerability information updated
Description
In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.
CVSS Metrics
- v3.1•MEDIUM•Score: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- v2.0•MEDIUM•Score: 4AV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 0.27%• Percentile: 50%
Techniques & Countermeasures
- CWE-639•Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Affected Systems
- Unknown•Cacti
≤ 1.2.6
References (10)
- https://github.com/Cacti/cacti/issues/2964
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZSCUUCKSYVZLN3PQE7NU76AFWUGT3E2D/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZO3ROHHPKLH2JRW7ES5FYSQTWIPNVLQB/
- https://seclists.org/bugtraq/2020/Jan/25
- https://www.debian.org/security/2020/dsa-4604
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.html
- https://security.gentoo.org/glsa/202003-40
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.html
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.html