Path Traversal Vulnerability in PRTG Network Monitor by Paessler
CVE-2023-31449

4.7MEDIUM

Key Information:

Vendor

Paessler

Vendor
CVE Published:
9 August 2023

What is CVE-2023-31449?

A path traversal vulnerability has been discovered in the WMI Custom sensor of PRTG Network Monitor, versions 23.2.84.1566 and earlier. This flaw allows an authenticated user with write permissions to manipulate the sensor into processing file paths incorrectly. As a result, the sensor could execute files that are located outside the intended directory for custom sensors. This exploit opens the door for potential unauthorized access to system files, thereby posing a significant risk to the integrity and confidentiality of the environment.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.