CVE-2022-0730

CRITICAL

Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

Affects 3 products across 3 vendors.

BCS6.96
CVSS 3.19.8
EPSS3.5%
Percentile88th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-287: Improper Authentication

Software does not prove or insufficiently proves that the user is who they claim to be.

Related Attack Patterns (CAPEC)
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-287
CAPEC-633 Token Impersonation
via CWE-287
CAPEC-650 Upload a Web Shell to a Web Server
via CWE-287
CAPEC-194 Fake the Source of Data
via CWE-287
CAPEC-593 Session Hijacking
via CWE-287
Show all 10

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in Cacti allows authentication bypass under specific LDAP conditions, posing a significant risk to system security.

BSID: BS-2022-GLOBAL-070083-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2022-0730?
A critical vulnerability in Cacti allows authentication bypass under specific LDAP conditions, posing a significant risk to system security.
What is the CVSS score for CVE-2022-0730?
CVE-2022-0730 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 3.5%.
Is CVE-2022-0730 actively exploited?
No confirmed active exploitation of CVE-2022-0730 as of 2026-05-30.
How do I remediate CVE-2022-0730?
Priority: IMMEDIATE. Advisory: https://www.debian.org/security/2022/dsa-5298
What systems are affected by CVE-2022-0730?
CVE-2022-0730 affects: Cacti, Debian, Fedoraproject.
Vulnerability Details
CVE IDCVE-2022-0730
BSIDBS-2022-GLOBAL-070083-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2022-03-03
Last Modified2024-11-21
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by providing specific credential types during the authentication process, which under certain LDAP configurations, can lead to unauthorized access without proper authentication.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cacti Cacti
Debian Debian Linux
Fedoraproject Fedora
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 1624 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash6da70f9514dac0c05a7ae471819bf28b15a172ccff026080870be4b9914e76483f30fe129c4350c9036878971b8e05c6ad1682b6ae825aab1edb6f0bf367629a
Related CVEs affecting Cacti
CVE-2024-29895 10.0 Cacti provides an operational monitoring and fault management framework. A co... CVE-2023-39361 9.8 Cacti is an open source operational monitoring and fault management framework... CVE-2022-46169 9.8 Cacti is an open source platform which provides a robust and extensible opera... CVE-2017-12065 9.8 spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute ... CVE-2025-26520 9.8 Cacti through 1.2.29 allows SQL injection in the template function in host_te...
View all Cacti CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →