CVE-2023-32782

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Aug 9, 2023
Updated: Aug 16, 2023
CWE ID 77

Summary

CVE-2023-32782 is a command injection vulnerability affecting PRTG Network Monitor versions 23.2.84.1566 and earlier. An authenticated user with write permissions can exploit the debug option in the Dicom C-ECHO sensor to write new files that could be executed by the EXE/Script sensor. The severity of this vulnerability is high, with a CVSS score of 7.2, as it allows attackers to gain control of the affected system and cause significant damage. Attackers can potentially steal sensitive data, modify configuration settings, and execute arbitrary code, making this a serious threat to organizations using PRTG Network Monitor.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • PRTG Network Monitor

Affected Vendors

  • Paessler AG