packetstormsecurity.com
http://packetstormsecurity.com/files/176677/PRTG-Authenticated-Remote-Code-Execution.html CVE-2023-32781
HIGH
PRTG CVE-2023-32781 Authenticated RCE
Record summary
CVE-2023-32781 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit.
Description
A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity of this vulnerability is high and received a score of 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
MetasploitPRTG CVE-2023-32781 Authenticated RCEMetasploit exploitby Kevin Joensen <kevin@baldur.dk>Not analyzed1 file
References
4kb.paessler.com
https://kb.paessler.com/en/topic/91845-multiple-vulnerabilites-fixed-in-paessler-prtg-network-monitor-23-3-86-1520 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-32781 paessler.com
https://www.paessler.com/prtg/history/stable