Executive brief
PRTG Network Monitor is a network monitoring platform used to track servers, devices, and infrastructure health. An authenticated attacker can write arbitrary files to the probe system through a vulnerability in the FTP Server Count Sensor, potentially allowing unauthorized modification of system files and gaining control over monitored infrastructure.
Technical details
The vulnerability is an arbitrary file write flaw in the FTP Server Count Sensor component of PRTG Network Monitor. The issue requires authentication and allows a privileged or authenticated user to write arbitrary files on the probe system where the sensor runs. The vulnerability was discovered during security testing and affects all versions before 23.1.82. The issue was patched in version 23.1.82 and Paessler recommends updating via the auto-update feature to remediate the vulnerability.
Affected products
- Paessler PRTG Network Monitor before 23.1.82
Timeline
- 2023-05: disclosed: Vulnerability reported and fixed in version 23.1.82
- 2023-05: patched: Fixed in PRTG 23.1.82