Record summary

CVE-2020-11547 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Repository PoCs

GitHubch-rigu/CVE-2020-11547--PRTG-Network-Monitor-Information-DisclosureRepository PoCby ch-riguStars: 4Not analyzed1 file

455 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMPRTG Network Monitor <20.1.57.1745 - Information DisclosureCVSS 5.3

PRTG Network Monitor before 20.1.57.1745 is susceptible to information disclosure. An attacker can obtain information about probes running or the server itself via an HTTP request, thus potentially being able to modify data and/or execute unauthorized administrative operations in the context of the affected site.

Impact

An attacker can exploit this vulnerability to gain sensitive information from the PRTG Network Monitor.

Remediation

Upgrade PRTG Network Monitor to version 20.1.57.1745 or higher to mitigate the information disclosure vulnerability.

WeaknessesCWE-306
Authorsx6263
Template tagscve2020cveprtgdisclosurepaesslervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:paessler:prtg_network_monitor:*:*:*:*:*:*:*:*
Shodan: title:"prtg"
Shodan: http.title:"prtg"
FOFA: title="prtg"
Google: intitle:"prtg"

Source: ProjectDiscovery

References

2