CVE-2024-29895
Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on th...
Affects 0 products across 2 vendors.
Attacker injects operating system commands through application inputs passed to a shell or system call.
Show all 8
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical command injection vulnerability exists in Cacti 1.3.x DEV branch, allowing unauthenticated users to execute arbitrary commands on the server if the PHP `register_argc_argv` option is enabled.
BSID: BS-2024-GLOBAL-269420-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2024-29895?
What is the CVSS score for CVE-2024-29895?
Is CVE-2024-29895 actively exploited?
How do I remediate CVE-2024-29895?
What systems are affected by CVE-2024-29895?
| CVE ID | CVE-2024-29895 |
|---|---|
| BSID | BS-2024-GLOBAL-269420-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2024-05-14 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `On`. In `cmd_realtime.php` line 119, the `$poller_id` used as part of the command execution is sourced from `$_SERVER['argv']`, which can be controlled by URL when `register_argc_argv` option of PHP is `On`. And this option is `On` by default in many environments such as the main PHP Docker image for PHP. Commit 53e8014d1f082034e0646edc6286cde3800c683d contains a patch for the issue, but this commit was reverted in commit 99633903cad0de5ace636249de16f77e57a3c8fc.
Source: NIST NVD / MITRE CVE Database
The vulnerability arises from the use of `$poller_id` in `cmd_realtime.php` line 119, which is sourced from `$_SERVER['argv']`. An attacker can manipulate this input to inject and execute arbitrary commands on the server.
Exploitation Likelihood: CRITICAL
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | a41bcee64bea86fd0a099e7662435d359985f37da1be80f53d0c11e868651e69250fea44b5beb34d10c24684f7524a2717ae04704091cc3a7d8d7fb5aedcc12d |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →