CISA KEV 정보
| 취약점명 | Paessler PRTG Network Monitor OS Command Injection Vulnerability |
|---|---|
| 설명 | Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console. |
| 조치사항 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
| 랜섬웨어 캠페인 악용 | Unknown |
| CWE | CWE-78 |
| 등록일 (KEV) | 2025-02-04 |
| 조치 기한 | 2025-02-25 |
| 추가 참고 | https://www.paessler.com/prtg/history/prtg-18#18.2.39 ; https://nvd.nist.gov/vuln/detail/CVE-2018-9276 |
NVD 상세 정보
CVSS v3.1: 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HCVSS v2.0: 9.0
AV:N/AC:L/Au:S/C:C/I:C/A:C설명: An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.
CWE: CWE-78 | CWE-78
참조
- http://packetstormsecurity.com/files/148334/PRTG-Command-Injection.html [Exploit, Mitigation, Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/161183/PRTG-Network-Monitor-Remote-Code-Execution.html [Exploit, Third Party Advisory, VDB Entry]
- http://www.securityfocus.com/archive/1/542103/100/0/threaded [Broken Link, Third Party Advisory, VDB Entry]
- https://www.exploit-db.com/exploits/46527/ [Exploit, Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/148334/PRTG-Command-Injection.html [Exploit, Mitigation, Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/161183/PRTG-Network-Monitor-Remote-Code-Execution.html [Exploit, Third Party Advisory, VDB Entry]
- http://www.securityfocus.com/archive/1/542103/100/0/threaded [Broken Link, Third Party Advisory, VDB Entry]
- https://www.exploit-db.com/exploits/46527/ [Exploit, Third Party Advisory, VDB Entry]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-9276 [US Government Resource]
This product uses the NVD API but is not endorsed or certified by the NVD.