Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls `compat_password_verify`. In `compat_password_verify`, `password_verify` is called if there is it, else use `md5`. `password_verify` and `password_hash` are supported on PHP < 5.5.0, following PHP manual. The vulnerability is in `compat_password_verify`. Md5-hashed user input is compared with correct password in database by `$md5 == $hash`. It is a loose comparison, not `===`. It is a type juggling vulnerability. Version 1.2.27 contains a patch for the issue.
In the `compat_password_verify` function, the MD5 hash of the password entered by the user is compared with the password stored in the database using the loose operator `==` instead of the strict `===`. In PHP, loose string comparison can lead to unexpected results when values can be interpreted as floating-point numbers (e.g., strings in scientific notation like `0e...` are compared as zero). An attacker can supply a crafted password whose MD5 hash satisfies the condition of loose comparison with the victim's password. The bug affects the verification path using MD5, activated on PHP < 5.5.0.
An unauthenticated remote attacker can bypass the login mechanism and gain unauthorized access to a user or administrator account in the Cacti application, leading to a violation of data confidentiality and integrity.
Cacti should be updated to version 1.2.27 or later, which contains a patch eliminating the vulnerability by replacing the loose comparison operator `==` with strict `===` in the `compat_password_verify` function
Cacti in versions before 1.2.27 and Cacti packages for Fedora and Debian using vulnerable versions
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NCacti
APPCacti< 1.2.27Fedora Project Fedora
OSFedoraproject39
Related vulnerabilities
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit
Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML
Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)
Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox
Integer overflow w Skia w Google Chrome — sandbox escape