Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-7237

Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.468
EPSS Ranking 97.5%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
References
Products affected by CVE-2020-7237
  • Cacti » Cacti » Version: 1.2.8
    cpe:2.3:a:cacti:cacti:1.2.8


Contact Us

Shodan ® - All rights reserved