Vulnerability Description
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paessler | Prtg Network Monitor | < 18.2.39 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/148334/PRTG-Command-Injection.htmlExploitMitigationThird Party Advisory
- http://packetstormsecurity.com/files/161183/PRTG-Network-Monitor-Remote-Code-ExeExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/542103/100/0/threadedBroken LinkThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46527/ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/148334/PRTG-Command-Injection.htmlExploitMitigationThird Party Advisory
- http://packetstormsecurity.com/files/161183/PRTG-Network-Monitor-Remote-Code-ExeExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/542103/100/0/threadedBroken LinkThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46527/ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-US Government Resource
FAQ
What is CVE-2018-9276?
CVE-2018-9276 is a vulnerability with a CVSS score of 7.2 (HIGH). An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injecti...
How severe is CVE-2018-9276?
CVE-2018-9276 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-9276?
Check the references section above for vendor advisories and patch information. Affected products include: Paessler Prtg Network Monitor.