Thursday, February 2, 2023
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Glossary
  • Community Forum
  • Web Hosting Directory
  • Login
  • Register
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Network/Internet
    • Windows
    • Software
    • Hardware
    • Blockchain
    • Policy/Legislation
    • How-Tos
    • Troubleshooting
No Result
View All Result
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Network/Internet
    • Windows
    • Software
    • Hardware
    • Blockchain
    • Policy/Legislation
    • How-Tos
    • Troubleshooting
No Result
View All Result
Cloud7 News
No Result
View All Result

Home > Cybersecurity > Unpatched Cacti servers are under attack

Unpatched Cacti servers are under attack

According to Censys, almost all Cacti servers are using an older version, which leaves the systems vulnerable to a combination of authentication bypass and command injection attacks.


Erdem Yasar Erdem Yasar
January 16, 2023
2 min read
Unpatched Cacti servers are under attack
  • Censys stated that only 26 of 6,427 observed Cacti hosts are running the patched version of the open-source solution.
  • Shadowserver Foundation published a post and stated that an unauthenticated remote command injection vulnerability is being exploited.
  • Cacti published an advisory about the vulnerability on December 5 and released the patched versions but the majority is still using older versions.

Attack surface management platform, Censys stated that they observed 6,427 Cacti hosts, an open-source network monitoring solution, hosts and most of them are running unpatched versions. Cacti released an advisory and stated that they have discovered a command injection vulnerability that allows an unauthenticated user to execute arbitrary code on a server running Cacti if a specific data source was selected for any monitored device. The vulnerability, tracked as CVE-2022-46169, is affecting all versions up to and including 1.2.22.

Being exploited

According to the Shadowserver Foundation’s post, the vulnerability is being exploited in the wild, since at least the 7th of January. However, Censys’ research shows that most of the organizations didn’t take the vulnerability seriously. Out of 6,427 hosts, only 26 are running one of the patched versions. 1,320 of these hosts are in Brazil, 795 in Indonesia, 254 in the United States, and 104 in China.

The patch was released with versions 1.2.23 and 1.3.0 to protect the users from the vulnerability with the CVSS score of 9.8. It is caused by how Cacti processes a specific HTTP query for a specific type of polling “action” defined in the database. According to the announcement, one of the query arguments used to execute these PHP scripts is not properly sanitized and is passed along to the execution call, resulting in a command injection. Also, another bug was discovered allowing attackers to bypass the authentication completely. Censys said,

« While not all monitoring software like Cacti has a known vulnerability (currently), this is no excuse to leave them facing publicly on the internet if they don’t have to be, especially since the data held within is highly valuable. Censys always suggests enabling authentication and placing monitoring services behind a VPN or VPC segment, along with proper IP filtering rules to ensure the internet doesn’t have any access to your critical resources.

Attackers can use other services like Cacti to obtain intel about an organization. For example, the system monitoring tool Netdata provides real-time, host-level system metrics about the device it is running on. It also does not come with authentication by default, meaning that anyone with a web browser can view the inner workings of a server and all of the juicy details contained within. And at the time of writing, there were over 30,000 internet-facing Netdata dashboards. »

See more Cybersecurity News


Tags: Cacti
Erdem Yasar

Erdem Yasar

Erdem Yasar is a news editor at Cloud7 News. Erdem started his career by writing video game reviews in 2007 for PC World magazine while he was studying computer engineering. In the following years, he focused on software development with various programming languages. After his graduation, he continued to work as an editor for several major tech-related websites and magazines. During the 2010s, Erdem Yasar shifted his focus to cloud computing, hosting, and data centers as they were becoming more popular topics in the tech industry. Erdem Yasar also worked with various industry-leading tech companies as a content creator by writing blog posts and other articles. Prior to his role at Cloud7 News, Erdem was the managing editor of T3 Magazine.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Next Post
Tencent Cloud is partnering with Traac for Europe expansion

Tencent Cloud is partnering with Traac for Europe expansion

Related News

APTs are looking for developers to hire with hefty paychecks

APTs are looking for developers to hire with hefty paychecks

February 1, 2023 2:30 pm
US extradites ShinyHunters hacker

US extradites ShinyHunters hacker

February 1, 2023 1:30 pm
Hacker steals code signing certificates for GitHub Desktop and Atom

Hacker steals code signing certificates for GitHub Desktop and Atom

February 1, 2023 1:00 pm
QNAP releases a patch for a new critical flaw affecting NAS devices

QNAP releases a patch for a new critical flaw affecting NAS devices

February 1, 2023 11:00 am
Get free daily newsletters from Cloud7 News Get the Cloud7 Newsletter
Select list(s):

Check your inbox or spam folder to confirm your subscription.

By subscribing, you agree to our
Copyright Policy and Privacy Policy

Get the free newsletter

Subscribe to receive the latest IT business updates straight to your inbox.

Select list(s):

Check your inbox or spam folder to confirm your subscription.

Editor's Choice

What’s new in Linux kernel 6.2 rc6?

10 Best Web Hosting Services of 2023

Ubuntu 22.04 LTS is available for download. What is new?

CERN and Fermilab recommend AlmaLinux

7 best hosting control panels of 2023

How to update Linux Kernel without rebooting?

7 best Linux mail servers of 2023

7 best cPanel alternatives for 2023

7 best Linux web browsers for 2023

7 best CentOS alternatives

7 best Linux server distros of 2023

Interview with Igor Seletskiy on AlmaLinux

How to create a VM on VMware Workstation

Recent News

  • Gcore introduces per-minute billing for video streaming
  • APTs are looking for developers to hire with hefty paychecks
  • F5 reports first quarter financial results
  • US extradites ShinyHunters hacker
  • Hacker steals code signing certificates for GitHub Desktop and Atom

Cloud7 News
Cloud7 is a news source that publishes the latest news, reviews, comparisons, opinions, and exclusive interviews to help tech users of high-experience levels in the IT industry.

EXPLORE

  • Web Hosting
  • Cloud Computing
  • Data Center
  • Cybersecurity
  • Linux
  • Network/Internet
  • Software
  • Hardware
  • How-Tos
  • Troubleshooting

RESOURCES

  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Glossary
  • Community Forum
  • Web Hosting Directory

Get the Cloud7 Newsletter

Get FREE daily newsletters from Cloud7 delivering the latest news and reviews.

  • About
  • Privacy & Policy
  • Copyright Policy
  • Contact

© 2023, Cloud7 News. All rights reserved.

No Result
View All Result
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Network/Internet
    • Windows
    • Software
    • Hardware
    • Blockchain
    • Policy/Legislation
    • How-Tos
    • Troubleshooting
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Glossary
  • Community Forum
  • Web Hosting Directory

© 2023, Cloud7 News. All rights reserved.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
Sign Up with Linked In
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.