Impact
A directory traversal flaw in Paessler PRTG Network Monitor (CWE-23) allows an attacker to read arbitrary files on the host system. By manipulating path parameters in HTTP requests, an attacker can request files outside the intended directory structure, exposing sensitive configuration data, credentials, or other confidential artifacts. The compromise is limited to information disclosure; there is no evidence that the flaw changes system state or provides execution capabilities.
Affected Systems
The vulnerability affects all releases of Paessler PRTG Network Monitor that are older than version 23.4.88.1429. Any installation running a pre‑patch version within the 23.4 series or earlier is susceptible to the directory traversal attack.
Risk and Exploitability
The flaw is rated with a CVSS score of 8.6, indicating high severity. EPSS score is <1%, and the issue is not listed in the CISA KEV catalog, suggesting no widely used or publicly disclosed exploit at this time. The likely attack vector requires network access to the PRTG web interface; the representation of this vector is inferred from the nature of the directory traversal vulnerability, as the official description does not explicitly specify the attacker’s required conditions.
OpenCVE Enrichment