Showing 4 vulnerabilities on this page for PRTG Network Monitor

Signals CISA KEV Ransomware Nuclei
Paessler vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability

Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. Some user interaction on the part of an administrator is required to exploit this vulnerability. The specific flaw exists within the PRTG Network Monitor web interface. The issue results from the lack of proper validation of user-supplied data, which can lead to the i

CWE-79Feb 11, 2025
CVSS6.1v3.1EPSS0.83%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability

Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the web console. The issue results from the lack of proper validation of user-supplied data, which can lead to the inje

CWE-79Feb 8, 2024
CVSS6.1v3.1EPSS1.75%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Paessler PRTG Network Monitor Local File Inclusion Vulnerability

PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including adm

Nov 21, 20181 related artifact
CVSS9.8v3.1EPSS86.6%PoCs1SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Paessler PRTG Network Monitor OS Command Injection Vulnerability

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.

CWE-78Jul 2, 2018
CVSS7.2v3.1EPSS87.2%PoCs7SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX