Vulnerability record · CVE-2023-39362 · published 5 September 2023
CVE-2023-39362: Cacti SNMP Options Command Injection Enables RCE
Cacti · Cacti
Cacti 1.2.24 fails to properly escape or validate variables passed into exec calls in lib/snmp.php, allowing command injection through the SNMP options of a Device. An authenticated privileged user can inject a malicious string and execute arbitrary commands on the underlying server. The flaw is fixed in Cacti 1.2.25 and no workarounds are documented.
Description
Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code execution on the underlying server. The `lib/snmp.php` file has a set of functions, with similar behavior, that accept in input some variables and place them into an `exec` call without a proper escape or validation. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw gives authenticated privileged users remote code execution on a monitoring server, public exploit code is referenced, and EPSS is extremely high, though exploitation requires valid high-privilege access.
What it is
Cacti 1.2.24 fails to properly escape or validate variables passed into exec calls in lib/snmp.php, allowing command injection through the SNMP options of a Device. An authenticated privileged user can inject a malicious string and execute arbitrary commands on the underlying server. The flaw is fixed in Cacti 1.2.25 and no workarounds are documented.
Impact
An attacker with privileged Cacti access gains remote code execution on the monitoring server, compromising the host and any data or credentials it holds. This can lead to full control of the Cacti instance and lateral movement into monitored infrastructure.
Attack surface
Reached over the network through the Cacti web interface by an authenticated privileged user who supplies a crafted string in a Device's SNMP options. No user interaction beyond that authenticated action is required, and the CVSS vector confirms network reachability with high privileges.
Exploitation
Public exploit references exist (Packetstorm and the vendor advisory are tagged Exploit), and EPSS is very high at 0.85332 (99.7th percentile), though CISA KEV does not list it. No ransomware group is documented as using it.
What to do
- Upgrade Cacti to version 1.2.25 or later immediately.
- If upgrade is not possible, restrict Cacti administrative and device-management access to trusted networks and accounts only.
- Audit and reduce the number of privileged Cacti users, applying least privilege.
- Monitor Cacti and Fedora/Debian package advisories for backported fixes and apply them.
- Review server logs and process execution for unexpected commands spawned by the web server user.
Detection
- Search Cacti and web server logs for SNMP option fields containing shell metacharacters such as ;, |, $(), or backticks.
- Monitor for child processes spawned by the Cacti web server user (e.g., www-data, apache, nginx) that are not expected SNMP or polling binaries.
- Alert on outbound network connections or file writes originating from the Cacti host outside normal polling behavior.
- Correlate Cacti device configuration changes with subsequent suspicious process execution on the Cacti server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-39362 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-39362), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.