SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-9276

Paessler PRTG Network Monitor OS Command Injection Vulnerability

KEVHIGH 7.2EPSS 87.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 25 February 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
87.00% probability · 100th percentile
CISA KEV
Listed 4 February 2025 · due 25 February 2025
Weakness
CWE-78
Affected
paessler/prtg network monitor
Source
cve@mitre.org

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://www.paessler.com/prtg/history/prtg-18#18.2.39 ; https://nvd.nist.gov/vuln/detail/CVE-2018-9276

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.