Cacti Security Update Advisory (CVE-2024-29895)

Overview

 

We have released an update to fix vulnerabilities in CACTI, a network equipment operations monitoring and fault management framework. users of affected versions are advised to update to the latest version.

 

Affected Products

 

CACTI versions: prior to 1.3.x DEV (excluded)

 

Resolved Vulnerabilities

 

Command Injection Vulnerability in Cacti (CVE-2024-29895)

 

Vulnerability Patches

 

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

Cacti version: 1.3.x DEV or at least (inclusive)

 

Referenced Sites

 

[1] https://nvd.nist.gov/vuln/detail/CVE-2024-29895

[2] https://github.com/Cacti/cacti/commit/53e8014d1f082034e0646edc6286cde3800c683d 

[3] https://github.com/Cacti/cacti/security/advisories/GHSA-cr28-x256-xf5m