CVE-2023-32781

A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity of this vulnerability is high and received a score of 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Configurations

Configuration 1 (hide)

cpe:2.3:a:paessler:prtg_network_monitor:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:04

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/176677/PRTG-Authenticated-Remote-Code-Execution.html - () http://packetstormsecurity.com/files/176677/PRTG-Authenticated-Remote-Code-Execution.html -
References () https://kb.paessler.com/en/topic/91845-multiple-vulnerabilites-fixed-in-paessler-prtg-network-monitor-23-3-86-1520 - Vendor Advisory () https://kb.paessler.com/en/topic/91845-multiple-vulnerabilites-fixed-in-paessler-prtg-network-monitor-23-3-86-1520 - Vendor Advisory
References () https://www.paessler.com/prtg/history/stable - Release Notes () https://www.paessler.com/prtg/history/stable - Release Notes

23 Jan 2024, 17:15

Type Values Removed Values Added
References
  • () http://packetstormsecurity.com/files/176677/PRTG-Authenticated-Remote-Code-Execution.html -
Summary
  • (es) Se identificó una vulnerabilidad de inyección de comandos en PRTG 23.2.84.1566 y versiones anteriores en el sensor HL7 donde un usuario autenticado con permisos de escritura podría abusar de la opción de depuración para escribir nuevos archivos que potencialmente podrían ser ejecutados por el sensor EXE/Script. La gravedad de esta vulnerabilidad es alta y ha recibido una puntuación de 7,2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Information

Published : 2023-08-09 12:15

Updated : 2024-11-21 08:04


NVD link : CVE-2023-32781

Mitre link : CVE-2023-32781

CVE.ORG link : CVE-2023-32781


JSON object : View

Products Affected

paessler

  • prtg_network_monitor
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')