CVE-2023-32781
Summary
| CVE | CVE-2023-32781 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-09 12:15:00 UTC |
| Updated | 2024-01-23 17:15:00 UTC |
| Description | A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity of this vulnerability is high and received a score of 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Paessler | Prtg Network Monitor | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PRTG Network Monitor - Version History | MISC | www.paessler.com | |
| PRTG Authenticated Remote Code Execution ≈ Packet Storm | packetstormsecurity.com | ||
| Multiple Vulnerabilites Fixed in Paessler PRTG Network Monitor 23.3.86.1520 | Paessler Knowledge Base | MISC | kb.paessler.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.