CVE-2020-10374
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.67% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- paessler/prtg network monitor
- Source
- cve@mitre.org
References
- https://kb.paessler.com/en/topic/87668-how-can-i-mitigate-cve-2020-10374-until-i-can-updateMitigation, Vendor Advisory
- https://tehtris.com/en/rce-on-prtg-network-monitor-tehtris-pentest/
- https://www.paessler.com/prtg/history/stable#20.1.57.1745Vendor Advisory
- https://kb.paessler.com/en/topic/87668-how-can-i-mitigate-cve-2020-10374-until-i-can-updateMitigation, Vendor Advisory
- https://tehtris.com/en/rce-on-prtg-network-monitor-tehtris-pentest/
- https://www.paessler.com/prtg/history/stable#20.1.57.1745Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.