← Global Threat Landscape

CVE-2022-46169

CWE-74

Critical

103.8

RPS

Description

Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides in the `remote_agent.php` file. This file can be accessed without authentication. This function retrieves the IP address of the client via `get_client_addr` and resolves this IP address to the corresponding hostname via `gethostbyaddr`. After this, it is verified that an entry within the `poller` table exists, where the hostname corresponds to the resolved hostname. If such an entry was found, the function returns `true` and the client is authorized. This authorization can be bypassed due to the implementation of the `get_client_addr` function. The function is defined in the file `lib/functions.php` and checks serval `$_SERVER` variables to determine the IP address of the client. The variables beginning with `HTTP_` can be arbitrarily set by an attacker. Since there is a default entry in the `poller` table with the hostn…

Source: NVD

Signals

CVSS
9.8
Critical · v3.1
EPSS
99.82%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Feb 2023
Fix commit
Fix commit known
Sources: MoreFixes, FreshFixes
Weakness
CWE-74
CWE-74, CWE-78
Published
5 Dec 2022
Last modified 24 Oct 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2022-46169

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2022-46169 · RPS 103.8 · DevSecure Intelligence