CVE-2014-2327
EPSS 0.42%
Description
Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users.
How to fix CVE-2014-2327
To remediate CVE-2014-2327, upgrade the affected package to a fixed version below.
- Debian/cacti—upgrade to 0.8.8b+dfsg-6 or later
Is CVE-2014-2327 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.8.8b+dfsg-6