{"api_version":"1","generated_at":"2026-07-23T21:14:41+00:00","cve":"CVE-2019-17358","urls":{"html":"https://cve.report/CVE-2019-17358","api":"https://cve.report/api/cve/CVE-2019-17358.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-17358","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-17358"},"summary":{"title":"CVE-2019-17358","description":"Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-12-12 14:15:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-787","CWE-502"],"metrics":[],"references":[{"url":"https://seclists.org/bugtraq/2020/Jan/25","name":"20200120 [SECURITY] [DSA 4604-1] cacti security update","refsource":"BUGTRAQ","tags":[],"title":"Bugtraq: [SECURITY] [DSA 4604-1] cacti security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.debian.org/security/2020/dsa-4604","name":"DSA-4604","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-4604-1 cacti","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.html","name":"openSUSE-SU-2020:0284","refsource":"SUSE","tags":[],"title":"[security-announce] openSUSE-SU-2020:0284-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/Cacti/cacti/commit/adf221344359f5b02b8aed43dfb6b33ae5d708c8","name":"https://github.com/Cacti/cacti/commit/adf221344359f5b02b8aed43dfb6b33ae5d708c8","refsource":"MISC","tags":["Product","Third Party Advisory"],"title":"Resoving Issue #3026 · Cacti/cacti@adf2213 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/Cacti/cacti/issues/3026","name":"https://github.com/Cacti/cacti/issues/3026","refsource":"MISC","tags":["Issue Tracking","Third Party Advisory"],"title":"When deserializating data, ensure basic sanitization has been performed · Issue #3026 · Cacti/cacti · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2019-17358","name":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2019-17358","refsource":"MISC","tags":["Issue Tracking","Third Party Advisory"],"title":"Bug 1158992 – VUL-0: CVE-2019-17358: cacti: Unsafe deserialization in sanitize_unserialize_selected_items","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.html","name":"openSUSE-SU-2020:0565","refsource":"SUSE","tags":[],"title":"[security-announce] openSUSE-SU-2020:0565-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-17358.html","name":"https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-17358.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"CVE-2019-17358 in Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2019/12/msg00014.html","name":"https://lists.debian.org/debian-lts-announce/2019/12/msg00014.html","refsource":"MISC","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] [DLA 2032-1] cacti security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.html","name":"openSUSE-SU-2020:0558","refsource":"SUSE","tags":[],"title":"[security-announce] openSUSE-SU-2020:0558-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.darkmatter.ae/xen1thlabs/","name":"https://www.darkmatter.ae/xen1thlabs/","refsource":"MISC","tags":["Not Applicable"],"title":"DarkMatter - Smart and Safe Digital |","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/202003-40","name":"GLSA-202003-40","refsource":"GENTOO","tags":[],"title":"Cacti: Multiple vulnerabilities (GLSA 202003-40) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.html","name":"openSUSE-SU-2020:0272","refsource":"SUSE","tags":[],"title":"[security-announce] openSUSE-SU-2020:0272-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/Cacti/cacti/blob/79f29cddb5eb05cbaff486cd634285ef1fed9326/lib/functions.php#L3109","name":"https://github.com/Cacti/cacti/blob/79f29cddb5eb05cbaff486cd634285ef1fed9326/lib/functions.php#L3109","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"cacti/functions.php at 79f29cddb5eb05cbaff486cd634285ef1fed9326 · Cacti/cacti · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-17358","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-17358","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"17358","vulnerable":"1","versionEndIncluding":"1.2.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cacti","cpe5":"cacti","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"17358","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"17358","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"17358","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"leap","cpe6":"42.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"17358","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"leap","cpe6":"42.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-17358","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.darkmatter.ae/xen1thlabs/","refsource":"MISC","name":"https://www.darkmatter.ae/xen1thlabs/"},{"url":"https://github.com/Cacti/cacti/blob/79f29cddb5eb05cbaff486cd634285ef1fed9326/lib/functions.php#L3109","refsource":"MISC","name":"https://github.com/Cacti/cacti/blob/79f29cddb5eb05cbaff486cd634285ef1fed9326/lib/functions.php#L3109"},{"refsource":"MISC","name":"https://lists.debian.org/debian-lts-announce/2019/12/msg00014.html","url":"https://lists.debian.org/debian-lts-announce/2019/12/msg00014.html"},{"refsource":"MISC","name":"https://github.com/Cacti/cacti/issues/3026","url":"https://github.com/Cacti/cacti/issues/3026"},{"refsource":"MISC","name":"https://github.com/Cacti/cacti/commit/adf221344359f5b02b8aed43dfb6b33ae5d708c8","url":"https://github.com/Cacti/cacti/commit/adf221344359f5b02b8aed43dfb6b33ae5d708c8"},{"refsource":"MISC","name":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2019-17358","url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2019-17358"},{"refsource":"MISC","name":"https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-17358.html","url":"https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-17358.html"},{"refsource":"BUGTRAQ","name":"20200120 [SECURITY] [DSA 4604-1] cacti security update","url":"https://seclists.org/bugtraq/2020/Jan/25"},{"refsource":"DEBIAN","name":"DSA-4604","url":"https://www.debian.org/security/2020/dsa-4604"},{"refsource":"SUSE","name":"openSUSE-SU-2020:0272","url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.html"},{"refsource":"SUSE","name":"openSUSE-SU-2020:0284","url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.html"},{"refsource":"GENTOO","name":"GLSA-202003-40","url":"https://security.gentoo.org/glsa/202003-40"},{"refsource":"SUSE","name":"openSUSE-SU-2020:0558","url":"http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.html"},{"refsource":"SUSE","name":"openSUSE-SU-2020:0565","url":"http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.html"}]},"impact":{"cvss":{"attackVector":"NETWORK","availabilityImpact":"NONE","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/A:N/C:H/I:H/PR:L/S:U/UI:N","version":"3.0"}}},"nvd":{"publishedDate":"2019-12-12 14:15:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-787","CWE-502"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":5.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*","versionEndIncluding":"1.2.7","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"17358","Ordinal":"157137","Title":"CVE-2019-17358","CVE":"CVE-2019-17358","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"17358","Ordinal":"1","NoteData":"Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"17358","Ordinal":"2","NoteData":"2019-12-12","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"17358","Ordinal":"3","NoteData":"2020-04-30","Type":"Other","Title":"Modified"}]}}}