Paessler Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Paessler products.
Products
- PRTG Network Monitor4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-12833MEDIUM | Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass VulnerabilityPaessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. Some user interaction on the part of an administrator is required to exploit this vulnerability. The specific flaw exists within the PRTG Network Monitor web interface. The issue results from the lack of proper validation of user-supplied data, which can lead to the i… CWE-79Feb 11, 2025 | CVSS6.1v3.1 | EPSS0.83% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-51630MEDIUM | Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass VulnerabilityPaessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the web console. The issue results from the lack of proper validation of user-supplied data, which can lead to the inje… CWE-79Feb 8, 2024 | CVSS6.1v3.1 | EPSS1.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-19410CRITICAL | Paessler PRTG Network Monitor Local File Inclusion VulnerabilityPRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including adm… Nov 21, 20181 related artifact | CVSS9.8v3.1 | EPSS86.6% | PoCs1 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2018-9276HIGH | Paessler PRTG Network Monitor OS Command Injection VulnerabilityAn issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios. CWE-78Jul 2, 2018 | CVSS7.2v3.1 | EPSS87.2% | PoCs7 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |