CVE-2020-11547
PRTG Network Monitor <20.1.57.1745 - Information Disclosure
Record summary
CVE-2020-11547 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.
Exploitation context
Proofs of concept
1Repository PoCs
GitHubch-rigu/CVE-2020-11547--PRTG-Network-Monitor-Information-DisclosureRepository PoCby ch-riguStars: 4Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMPRTG Network Monitor <20.1.57.1745 - Information DisclosureCVSS 5.3
PRTG Network Monitor before 20.1.57.1745 is susceptible to information disclosure. An attacker can obtain information about probes running or the server itself via an HTTP request, thus potentially being able to modify data and/or execute unauthorized administrative operations in the context of the affected site.
Impact
An attacker can exploit this vulnerability to gain sensitive information from the PRTG Network Monitor.
Remediation
Upgrade PRTG Network Monitor to version 20.1.57.1745 or higher to mitigate the information disclosure vulnerability.
Source: ProjectDiscovery