Impact
PRTG Network Monitor versions prior to 23.1.82 contain a flaw that allows a remote attacker to write to arbitrary files by sending specially crafted XML/REST requests to the HTTP interface. This remote file write capability could be used to overwrite configuration files or facilitate further compromise on the monitored host.
Affected Systems
The vulnerability affects Paessler PRTG Network Monitor releases older than 23.1.82. Any installation that has not been upgraded to 23.1.82 or later remains vulnerable.
Risk and Exploitability
The CVSS score of 2.7 indicates low severity. The EPSS score of < 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires network access to the PRTG instance, exposure over the internet or to untrusted networks increases risk, but exposure on a secured internal network reduces the likelihood of an attack.
OpenCVE Enrichment