Path Traversal Vulnerability in PRTG Network Monitor by Paessler
CVE-2023-31450

4.7MEDIUM

Key Information:

Vendor

Paessler

Vendor
CVE Published:
9 August 2023

What is CVE-2023-31450?

A path traversal vulnerability exists in the SQL v2 sensors of PRTG Network Monitor versions 23.2.84.1566 and earlier. This flaw allows an authenticated user with write permissions to manipulate the SQL v2 sensors, enabling them to access files beyond the intended directory structure. By exploiting this vulnerability, attackers could potentially execute unauthorized commands or scripts, leading to severe security implications for the system.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.