CVE-2018-9276
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- April 04, 2018
- Published Date
- July 02, 2018
- Last Updated
- February 04, 2025
- Vendor
- n/a
- Product
- n/a
- Description
- An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C
SSVC Information
- Exploitation
- active
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2025-02-04 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/prtg_authenticated_rce.rb | 2025-04-29 11:01:39 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
prtg_authenticated_rce
Type: metasploit • Created: Unknown
alvinsmith-eroad/CVE-2018-9276
Type: github • Created: 2021-07-29 09:08:18 UTC • Stars: 0
andyfeili/CVE-2018-9276
Type: github • Created: 2021-01-02 09:08:42 UTC • Stars: 0
wildkindcc/CVE-2018-9276
Type: github • Created: 2019-03-31 08:51:07 UTC • Stars: 36