Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadgets are not included, making them inaccessible and the insecure deserializations not exploitable. Each instance of insecure deserialization is due to using the unserialize function without sanitizing the user input. Cacti has a “safe” deserialization that attempts to sanitize the content and check for specific values before calling unserialize, but it isn’t used in these instances. The vulnerable code lies in graphs_new.php, specifically within the host_new_graphs_save function. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Conclusion & alert: CVE-2023-30534 is rated Exploit Available (56.3/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 2.57%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 52.47% | 2.57% | -49.90% |
| 2 | 2026-06-10 | 54.95% | 52.47% | -2.48% |
| 3 | 2026-04-28 | — | 54.95% | — |
Full EPSS history (57 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.3 | 3.1 | MEDIUM |
|
2.8 | 1.4 | [email protected] |
| 4.3 | 3.1 | MEDIUM |
|
2.8 | 1.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2023-30534: 1 source package rows (cacti); 14 state rows across 6 repos (3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 5, open 9. | https://security.alpinelinux.org/vuln/CVE-2023-30534 |
debian
|
not yet assigned | CVE-2023-30534 not yet assigned priority: Debian including 1 source packages (cacti), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 3, open 2. | https://security-tracker.debian.org/tracker/CVE-2023-30534 |
gentoo
|
high | CVE-2023-30534: 1 GLSA(s) (202412-02), 1 atom(s) (net-analyzer/cacti); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2023-30534 |
ubuntu
|
medium | CVE-2023-30534 medium priority: Ubuntu including 1 source packages (cacti), 12 status rows across 12 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): needs-triage 6, not-affected 3, ignored 2, released 1. | https://ubuntu.com/security/CVE-2023-30534 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cacti | cacti | < 1.2.25 | cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:* |
| fedoraproject | fedora | 37 | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
| fedoraproject | fedora | 38 | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |