CVE-2018-9276
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- April 04, 2018
- Published Date
- July 02, 2018
- Last Updated
- February 04, 2025
- Vendor
- Paessler AG
- Product
- PRTG Network Monitor
- Description
- An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.
- Tags
- Exploitation
- active
- Technical Impact
- total
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C
SSVC Information
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2025-02-04 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/prtg_authenticated_rce.rb | 2025-04-29 11:01:39 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
prtg_authenticated_rce
Type: metasploit • Created: Unknown
alvinsmith-eroad/CVE-2018-9276
Type: github • Created: 2021-07-29 09:08:18 UTC • Stars: 0
andyfeili/CVE-2018-9276
Type: github • Created: 2021-01-02 09:08:42 UTC • Stars: 0
wildkindcc/CVE-2018-9276
Type: github • Created: 2019-03-31 08:51:07 UTC • Stars: 36
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Added to KEVIntel
-
Detected by Metasploit