Vulnerability Description
A path traversal vulnerability was identified in the HL7 sensor in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the HL7 sensor into behaving differently for existing files and non-existing files. This made it possible to traverse paths, allowing the sensor to execute files outside the designated custom sensors folder. The severity of this vulnerability is medium and received a score of 4.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paessler | Prtg Network Monitor | < 23.3.86.1520 |
Related Weaknesses (CWE)
References
- https://kb.paessler.com/en/topic/91845-multiple-vulnerabilites-fixed-in-paesslerVendor Advisory
- https://www.paessler.com/prtg/history/stableRelease Notes
- https://kb.paessler.com/en/topic/91845-multiple-vulnerabilites-fixed-in-paesslerVendor Advisory
- https://www.paessler.com/prtg/history/stableRelease Notes
FAQ
What is CVE-2023-31448?
CVE-2023-31448 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A path traversal vulnerability was identified in the HL7 sensor in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the HL7 sensor into behaving di...
How severe is CVE-2023-31448?
CVE-2023-31448 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-31448?
Check the references section above for vendor advisories and patch information. Affected products include: Paessler Prtg Network Monitor.