Executive brief
Paessler PRTG is a network monitoring platform used by over 500,000 organizations to track system performance and availability. A path traversal vulnerability in the PRTG webserver allows unauthenticated attackers to read arbitrary local files from the server, potentially exposing sensitive configuration data, credentials, or other confidential information without requiring any authentication.
Technical details
A path traversal (directory traversal) vulnerability was identified in the PRTG webserver component, allowing attackers to access files outside the intended directory by manipulating file path parameters. The vulnerability is exploitable without authentication, meaning any network-accessible attacker can trigger it. By crafting malicious requests with traversal sequences (e.g., ../ or similar), an attacker can read arbitrary files from the server's filesystem. The vulnerability was fixed in PRTG version 23.4.88.1429 and later. No evidence of active exploitation in the wild has been reported as of the advisory date.
Affected products
- Paessler PRTG before 23.4.88.1429
Timeline
- 2023-10-16: disclosed: CVE-ID published
- 2023-10-16: patched: Fixed in version 23.4.88.1429