Learn about CVE-2019-17358, a vulnerability in Cacti versions 1.2.7 and earlier allowing authenticated attackers to manipulate object data values. Find mitigation steps and the impact of this security issue.
Cacti versions 1.2.7 and earlier are vulnerable to multiple cases of unsafe deserialization of user-controlled data in lib/functions.php, allowing an authenticated attacker to manipulate object data values and control Cacti's actions. This could potentially lead to memory corruption in the PHP module.
Understanding CVE-2019-17358
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module.
What is CVE-2019-17358?
The Impact of CVE-2019-17358
Technical Details of CVE-2019-17358
Cacti versions 1.2.7 and earlier are susceptible to unsafe deserialization, potentially leading to memory corruption.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
It is crucial to take immediate steps to address and prevent exploitation of CVE-2019-17358.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates