PT-2018-1931 · Paessler · Prtg Network Monitor

Dmitry Galecha

·

Publicado

2018-05-07

·

Atualizado

2025-03-14

·

CVE-2018-19410

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PRTG Network Monitor versions prior to 18.2.40.1683
Description The issue is related to insecure privilege management in PRTG Network Monitor, allowing remote unauthenticated attackers to create users with read-write privileges, including administrators. This can be achieved by crafting an HTTP request to override attributes of the 'include' directive in /public/login.htm, performing a Local File Inclusion attack by including and executing /api/addusers. The attack involves providing the id and users parameters.
Recommendations For versions prior to 18.2.40.1683, update to version 18.2.40.1683 or later to resolve the issue. As a temporary workaround, consider restricting access to the /public/login.htm and /api/addusers endpoints to minimize the risk of exploitation. Additionally, restrict the use of the id and users parameters in the affected API endpoint until the issue is resolved.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01538
CVE-2018-19410

Produtos afetados

Prtg Network Monitor