ZeroHour

CVE-2023-45858

moderate

Unauthenticated Path Traversal File Read in Paessler PRTG Network Monitor

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2023-45858 is a directory traversal flaw (CWE-23) in Paessler PRTG Network Monitor before version 23.4.88.1429 that allows an unauthenticated remote attacker to read arbitrary local files on the PRTG server by sending crafted path-traversal sequences to the product's web interface. Because PRTG is a monitoring platform that stores configuration and credential material on the host, successful exploitation can expose sensitive files such as device credentials, network topology details, and OS-level files readable by the PRTG service account. The issue is rated CVSS 3.1 8.6 (high) with network attack vector, no privileges and no user interaction required, though it impacts confidentiality only. Any on-premises PRTG Core Server running a version older than 23.4.88.1429 is affected, including any instance whose web interface is reachable from the internet. No public proof of concept is known and the flaw is not on the CISA KEV catalog, so no in-the-wild exploitation has been confirmed.

What to do: Upgrade PRTG Network Monitor to version 23.4.88.1429 or later, which remediates the traversal. Restrict the PRTG web interface to trusted management networks or VPN rather than exposing it to the internet, and review web server logs for anomalous requests containing path-traversal sequences. Because file disclosure may leak stored credentials, rotate any device and service credentials stored in affected instances if compromise is suspected.

Affected
Paessler PRTG Network Monitorbefore 23.4.88.1429 (all prior on-premises versions)
Estimated exposure
moderate≈5,000–10,000 internet-exposed PRTG web interfaces, plus a larger internal/VPN-only install base — Internet-wide scan services (Shodan/Censys) consistently show a few thousand PRTG web frontends directly exposed, while the total customer base of the on-premises product is larger but mostly internal-facing.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.

Weakness
CWE-23
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.