Record summary

CVE-2023-32781 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit.

Description

A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity of this vulnerability is high and received a score of 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

MetasploitPRTG CVE-2023-32781 Authenticated RCEMetasploit exploitby Kevin Joensen <kevin@baldur.dk>Not analyzed1 file

Ruby

Metasploit

PoC details

References

4