High severity8.8NVD Advisory· Published Jan 20, 2020· Updated Jun 17, 2026
CVE-2020-7237
CVE-2020-7237
Description
Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- Cacti/Cactidescription
=1.2.8+ 1 more
- (no CPE)range: =1.2.8
- cpe:2.3:a:cacti:cacti:1.2.8:*:*:*:*:*:*:*
- osv-coords7 versionspkg:rpm/opensuse/cacti&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/opensuse/cacti&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/cacti-spine&distro=openSUSE%20Leap%2015.1
< 1.2.9-lp151.3.3.1+ 6 more
- (no CPE)range: < 1.2.9-lp151.3.3.1
- (no CPE)range: < 1.2.11-5.1
- (no CPE)range: < 1.2.11-2.1
- (no CPE)range: < 1.2.9-bp151.4.3.1
- (no CPE)range: < 1.2.9-bp151.4.3.1
- (no CPE)range: < 1.2.18-1.2
- (no CPE)range: < 1.2.9-lp151.3.3.1
Patches
Vulnerability mechanics
References
9- github.com/Cacti/cacti/issues/3201nvdExploitThird Party Advisory
- ctrsec.io/index.php/2020/01/25/cve-2020-7237-remote-code-execution-in-cacti-rrdtool/nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SUSOTOIEJKD2IWJHN7TY56TDZJQZJUVJ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XLZAMGTW2OSIBLYLXWHQBGWP7M4DTRS7/nvd
- security.gentoo.org/glsa/202003-40nvd
News mentions
0No linked articles in our index yet.