PT-2025-45113 · Dynatrace · Dynatrace Activegate

Published

2025-11-05

·

Updated

2025-11-08

·

CVE-2025-61304

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dynatrace ActiveGate versions up to 1.016
Description An OS command injection issue exists in the Dynatrace ActiveGate ping extension. This flaw allows for potential code execution through the use of specially crafted IP addresses. The ping extension is susceptible to this issue, potentially enabling an attacker to inject and execute arbitrary operating system commands. The vulnerable component processes IP addresses without sufficient validation, leading to the possibility of command injection. The affected parameter is the IP address provided to the ping extension.
Recommendations Update Dynatrace ActiveGate to a version beyond 1.016.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-61304

Affected Products

Dynatrace Activegate