CVE-2018-9276
גבוהה 7.2 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Paessler PRTG Network Monitor OS Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.
מדדים
- CVSS 3.1
-
7.2 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 87% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-78
מוצרים מושפעים
paessler: prtg network monitor
קישורים
- http://packetstormsecurity.com/files/148334/PRTG-Command-Injection.html ExploitMitigationThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161183/PRTG-Network-Monitor-Remote-Code-E… ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46527/ ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/148334/PRTG-Command-Injection.html ExploitMitigationThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161183/PRTG-Network-Monitor-Remote-Code-E… ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46527/ ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/542103/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/542103/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource