PRTG
by Paessler
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10374 | Cri | 0.64 | 9.8 | 0.05 | Mar 30, 2020 | A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form. | ||
| CVE-2018-14683 | Med | 0.40 | 6.1 | 0.01 | Apr 10, 2019 | PRTG before 19.1.49.1966 has Cross Site Scripting (XSS) in the WEBGUI. | ||
| CVE-2016-5078 | Med | 0.40 | 6.1 | 0.01 | Apr 10, 2017 | Paessler PRTG before 16.2.24.4045 has XSS via SNMP. | ||
| CVE-2019-19119 | Med | 0.36 | 5.5 | 0.00 | Feb 3, 2020 | An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a non-administrative user on the local machine is able to access administrative credentials. |
- risk 0.64cvss 9.8epss 0.05
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form.
- risk 0.40cvss 6.1epss 0.01
PRTG before 19.1.49.1966 has Cross Site Scripting (XSS) in the WEBGUI.
- risk 0.40cvss 6.1epss 0.01
Paessler PRTG before 16.2.24.4045 has XSS via SNMP.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a non-administrative user on the local machine is able to access administrative credentials.