Remote Code Execution Vulnerability in PRTG Network Monitor by Paessler
CVE-2018-19204

8.8HIGH

Key Information:

Vendor

Paessler

Vendor
CVE Published:
12 November 2018

What is CVE-2018-19204?

The PRTG Network Monitor prior to version 18.3.44.2054 has a vulnerability that allows remote authenticated users with read-write privileges to execute arbitrary code. The issue arises when handling user input in the HTTP Advanced Sensor's POST parameter 'proxyport_'. An attacker can craft a specific HTTP request to manipulate the 'writeresult' command-line parameter for HttpAdvancedSensor.exe, thereby gaining the ability to store and execute arbitrary data within the system's file structure. This threat presents significant risks, particularly through the unauthorized creation of executable files in sensitive directories.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.