CVE-2018-9276
high · 7.2Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Added 2025-02-04Remediation due 2025-02-25
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.
7.2
CVSS
87.0%
EPSS (exploit prob.)
100th
EPSS percentile
2018-07-02
Published
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| paessler | prtg_network_monitor | < 18.2.39 |
| paessler | prtg_network_monitor | > 19.3.52, < 21.2.68 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/148334/PRTG-Command-Injection.html
- http://packetstormsecurity.com/files/161183/PRTG-Network-Monitor-Remote-Code-Execution.html
- http://www.securityfocus.com/archive/1/542103/100/0/threaded
- https://www.exploit-db.com/exploits/46527/
- http://packetstormsecurity.com/files/148334/PRTG-Command-Injection.html
- http://packetstormsecurity.com/files/161183/PRTG-Network-Monitor-Remote-Code-Execution.html
- http://www.securityfocus.com/archive/1/542103/100/0/threaded
- https://www.exploit-db.com/exploits/46527/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-9276
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-9276