Access Control Vulnerability in PRTG Monitoring Software by Paessler
CVE-2019-19119

5.5MEDIUM

Key Information:

Vendor

Paessler

Vendor
CVE Published:
3 February 2020

What is CVE-2019-19119?

A significant security flaw exists in PRTG Network Monitor versions 7.x through 19.4.53, which stems from inadequate access control on local registry keys associated with the Core Server Service. This oversight allows non-administrative users on the local machine to gain unauthorized access to administrative credentials, potentially leading to unauthorized control over the monitoring software and sensitive data.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.