Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no need to complete the steps before or after it) to use a php file as the cacti log file. After having the malicious hostname end up in the logs (log poisoning), one can simply go to the log file url to execute commands to achieve RCE. This issue has been addressed in version 1.2.28 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Conclusion & alert: CVE-2024-43363 is rated High Exploit Risk (81/100): CVSS High severity, with high exploitation likelihood (EPSS 75.13%, 99th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +2.61% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-27 | 72.52% | 75.13% | +2.61% |
| 2 | 2026-03-23 | 70.27% | 72.52% | +2.25% |
| 3 | 2026-02-21 | — | 70.27% | — |
Full EPSS history (26 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.2 | 3.1 | HIGH |
|
1.2 | 5.9 | [email protected] |
| 7.2 | 3.1 | HIGH |
|
1.2 | 5.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2024-43363: 1 source package rows (cacti); 22 state rows across 4 repos (3.20-community, 3.21-community, 3.22-community, edge-community); fixed 7, open 15. | https://security.alpinelinux.org/vuln/CVE-2024-43363 |
debian
|
unimportant | CVE-2024-43363 unimportant priority: Debian including 1 source packages (cacti), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2024-43363 |
ubuntu
|
medium | CVE-2024-43363 medium priority: Ubuntu including 1 source packages (cacti), 10 status rows across 10 suites (bionic, focal, jammy, noble, oracular, plucky, questing, trusty, upstream, xenial): needs-triage 8, ignored 2. | https://ubuntu.com/security/CVE-2024-43363 |
| URL | Tags |
|---|---|
| https://github.com/Cacti/cacti/security/advisories/GHSA-gxq4-mv8h-6qj4 | Exploit Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/02/msg00010.html |