Path Traversal Vulnerability in PRTG Network Monitor by Paessler
CVE-2023-31448

4.7MEDIUM

Key Information:

Vendor

Paessler

Vendor
CVE Published:
9 August 2023

What is CVE-2023-31448?

A path traversal vulnerability exists in the HL7 sensor within PRTG Network Monitor versions 23.2.84.1566 and earlier. An authenticated user with write permissions can exploit this flaw by manipulating the HL7 sensor's handling of file paths. This exploitation could lead to unauthorized access, allowing the sensor to execute files located outside its designated custom sensors directory. This creates potential security concerns regarding sensitive information and file integrity.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.