Executive brief
PRTG Network Monitor is a widely used tool for monitoring the health and performance of IT infrastructure. A security vulnerability in older versions allows an authorized user to read sensitive files from the server hosting the software. This could lead to the exposure of configuration details, credentials, or other private data, potentially allowing an attacker to expand their access within the corporate network.
Technical details
An XML External Entity (XXE) vulnerability exists in the way PRTG Network Monitor processes XML data when creating specific sensor types. Specifically, the 'HTTP XML/REST Value' sensor fails to properly restrict external entity references. A remote authenticated attacker can exploit this by creating a new sensor and pointing it at a maliciously crafted XML file. This allows the attacker to perform an out-of-band data exfiltration or directly read local files on the PRTG server's file system. The issue is resolved in versions 16.2.23.3077 and 16.2.23.3078.
Affected products
- Paessler PRTG Network Monitor before 16.2.23.3077/3078
Timeline
- 2015-10-06: disclosed: CVE reserved date
- 2017-01-23: advisory: NVD publication date