Command Injection Vulnerability in PRTG Could Lead to Execution of Malicious Code
CVE-2023-32782

7.2HIGH

Key Information:

Vendor

Paessler

Vendor
CVE Published:
9 August 2023

What is CVE-2023-32782?

A command injection vulnerability has been discovered in PRTG Network Monitor, specifically within the Dicom C-ECHO sensor. This issue allows an authenticated user with write permissions to exploit the debug option, enabling the modification and creation of files. These files can be executed by the EXE/Script sensor, posing a risk of unauthorized actions being performed on the system. It is crucial for users and administrators of PRTG Network Monitor to address this vulnerability by updating to the latest patched versions to mitigate potential security threats.

References

EPSS Score

56% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.