Information Disclosure Vulnerability in PRTG Network Monitor by Paessler AG
CVE-2020-11547
Key Information:
- Vendor
Paessler
- Status
- Vendor
- CVE Published:
- 5 April 2020
Badges
What is CVE-2020-11547?
An information disclosure vulnerability exists in PRTG Network Monitor prior to version 20.1.57.1745, allowing remote unauthenticated attackers to gather sensitive system information. By crafting specific HTTP requests to the application, attackers can reveal critical metrics, such as CPU usage, memory utilization, operating system version, and other internal statistics of the monitoring tools. Such exposure can lead to further exploitation or reconnaissance activities, emphasizing the importance of timely updates and security configurations.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
52% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
