Impact
The flaw appears in the FTP Server Count Sensor component of PRTG before version 23.1.82, permitting an attacker to craft requests that result in arbitrary file creation or modification on the monitored host. Because the file system remains writable, an adversary could potentially create or alter configuration or log files, leading to further exploitation. The weakness maps to CWE‑88 (Resource Conflict or Race Condition).
Affected Systems
Paessler PRTG Network Monitor versions earlier than 23.1.82 are affected. The issue originates solely in the FTP Server Count Sensor module. Systems running the sensor without patch remain vulnerable.
Risk and Exploitability
The CVSS score of 2.7 indicates low severity, and without a publicly available exploit the probability of exploitation remains uncertain. However, the vulnerability enables remote attackers to write files from outside the system, which could serve as a foothold for further compromise, especially if the target user has elevated privileges. Because EPSS is not available and the vulnerability is not listed in KEV, it is unclear whether active exploitation is occurring. Administrators should consider the potential for privilege escalation when assessing exposure.
OpenCVE Enrichment