S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-8813 Scanner

CVE-2020-8813 scanner - Unauthenticated Remote Code Execution vulnerability in Cacti

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-8813
8.8
CVSS

graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Cacti software is an open-source network monitoring and graphing tool designed to track and analyze different types of network data. The product features a web-based front end and provides various functions such as data visualization, data collection, and reporting. It is widely used by IT professionals, network administrators, and system administrators to identify and troubleshoot network issues, detect potential bottlenecks, and optimize overall network performance.

CVE-2020-8813 is a vulnerability that was recently detected in Cacti 1.2.8, which allows remote attackers to execute arbitrary OS commands through shell metacharacters in a cookie. This vulnerability can be exploited by guest users with graph real-time privilege, allowing remote attackers to penetrate the network and take unauthorized control of the system.

When exploited, this vulnerability can lead to severe consequences, such as unauthorized data access, system crashes, and loss of sensitive information. Attackers can also use this to model future attack vectors that could potentially compromise the entire network as well. As a result, it is essential to take immediate action to protect against this type of vulnerability.

In conclusion, security is a top concern in today's increasingly digital world, and it is crucial to stay up-to-date with the latest security vulnerabilities. By utilizing the s4e.io platform, users can easily and quickly learn about any vulnerabilities in their digital assets, thanks to the platform's pro features. As such, it is essential to note the importance of staying aware of such platforms to ensure maximum security for your digital assets.

 

REFERENCES

Solution Advice

Here are some precautions that can be taken to protect against this vulnerability:

  • Upgrade Cacti software to the latest version
  • Restrict guest access to the system
  • Monitor system logs and look for any suspicious activity
  • Implement firewalls and antivirus software on the system
  • Disable shell access to the system

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.