KEVIntel
7.2
CVSS
High

CVE-2018-9276

PUBLISHED

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with...

Exploited in the wild Remote Low complexity No user interaction
Vendor
Paessler AG
Product
PRTG Network Monitor
Published
Jul 02, 2018
EPSS

Description

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.

ios cisa metasploit

CVSS scores

CVSS v3.1 7.2 High

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 9.0

AV:N/AC:L/Au:S/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2025-02-04 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Feb 04, 2025

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

prtg_authenticated_rce

metasploit · Created Unknown

Metasploit module for CVE-2018-9276

alvinsmith-eroad/CVE-2018-9276

github · Created 2021-07-29 09:08:18 UTC · 0 stars

CVE-2018-9276 PRTG < 18.2.39 Reverse Shell (Python3 support)

andyfeili/CVE-2018-9276

github · Created 2021-01-02 09:08:42 UTC · 0 stars

wildkindcc/CVE-2018-9276

github · Created 2019-03-31 08:51:07 UTC · 36 stars

CVE-2018-9276 PRTG < 18.2.39 Authenticated Command Injection (Reverse Shell)

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Metasploit