← All CVEs

CVE-2018-9276

high · 7.2Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added 2025-02-04Remediation due 2025-02-25

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.

7.2
CVSS
87.0%
EPSS (exploit prob.)
100th
EPSS percentile
2018-07-02
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
paesslerprtg_network_monitor< 18.2.39
paesslerprtg_network_monitor> 19.3.52, < 21.2.68

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-9276