PT-2025-45113 · Dynatrace · Dynatrace Activegate
Published
2025-11-05
·
Updated
2025-11-08
·
CVE-2025-61304
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dynatrace ActiveGate versions up to 1.016
Description
An OS command injection issue exists in the Dynatrace ActiveGate ping extension. This flaw allows for potential code execution through the use of specially crafted IP addresses. The
ping extension is susceptible to this issue, potentially enabling an attacker to inject and execute arbitrary operating system commands. The vulnerable component processes IP addresses without sufficient validation, leading to the possibility of command injection. The affected parameter is the IP address provided to the ping extension.Recommendations
Update Dynatrace ActiveGate to a version beyond 1.016.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dynatrace Activegate