Skip to main content

Vendor/product archive

paessler / prtg_network_monitor CVEs

Beta · best-effort

39 CVEs tagged to paessler / prtg_network_monitor2 Critical, 10 High, 27 Medium, 0 Low, 0 Unrated.

CVE-2018-19410

Published Nov 21, 2018

PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated use…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2018-19204

Published Nov 12, 2018

PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with system privileges. When…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19203

Published Nov 12, 2018

PRTG Network Monitor before 18.2.41.1652 allows remote unauthenticated attackers to terminate the PRTG Core Server Service via a special HTTP request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9276

Published Jul 2, 2018

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit…

CVSS 7.2 · High
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2017-15917

Published Oct 26, 2017

In Paessler PRTG Network Monitor 17.3.33.2830, it's possible to create a Map as a read-only user, by forging a request and sending it to the server.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15651

Published Oct 20, 2017

PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .exe file and then proceeding in spite of the error message.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15360

Published Oct 15, 2017

PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all group names created, related to incorrect error handling for an HTML encoded script.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15009

Published Oct 4, 2017

PRTG Network Monitor version 17.3.33.2830 is vulnerable to reflected Cross-Site Scripting on error.htm (the error page), via the errormsg parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15008

Published Oct 4, 2017

PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all sensor titles, related to incorrect error handling for a %00 in the SRC attribute of…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12879

Published Aug 24, 2017

Cross-site scripting (XSS-STORED) vulnerability in the DEVICES OR SENSORS functionality in Paessler PRTG Network Monitor before 17.3.33.2654 allows authenticated remote attackers…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9816

Published Aug 18, 2017

Cross-site scripting (XSS) vulnerability in Paessler PRTG Network Monitor before 17.2.32.2279 allows remote attackers to inject arbitrary web script or HTML via unspecified vector…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7743

Published Jan 23, 2017

XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-39 of 39 CVEsPage 2 of 2