CVE-2018-19204
Last modified
CVE-2018-19204 is a vulnerability of currently unknown severity. PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with system privileges. When creating an HTTP Advanced Sensor, the user's input in the POST parameter 'proxyport_' is mishandled. EPSS estimates a 4.64% chance of exploitation in the next 30 days.
Description
PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with system privileges. When creating an HTTP Advanced Sensor, the user's input in the POST parameter 'proxyport_' is mishandled. The attacker can craft an HTTP request and override the 'writeresult' command-line parameter for HttpAdvancedSensor.exe to store arbitrary data in an arbitrary place on the file system. For example, the attacker can create an executable file in the \Custom Sensors\EXE directory and execute it by creating EXE/Script Sensor.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Paessler | Prtg Network Monitor | < 18.3.44.2054 |
References
- http://en.securitylab.ru/lab/PT-2018-23Third Party Advisory
- https://www.paessler.com/prtg/history/stable#18.3.44.2054Vendor Advisory
- https://www.ptsecurity.com/ww-en/analytics/threatscape/pt-2018-23/Third Party Advisory
- http://en.securitylab.ru/lab/PT-2018-23Third Party Advisory
- https://www.paessler.com/prtg/history/stable#18.3.44.2054Vendor Advisory
- https://www.ptsecurity.com/ww-en/analytics/threatscape/pt-2018-23/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-19204?
How severe is CVE-2018-19204?
How do I fix CVE-2018-19204?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-19199An issue was discovered in uriparser before 0.9.0. UriQuery.…
- CVE-2018-1920IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable t…7.1
- CVE-2018-19200An issue was discovered in uriparser before 0.9.0. UriCommon…
- CVE-2018-19201A reflected XSS vulnerability in the ModCP Profile Editor in…
- CVE-2018-19202A reflected XSS vulnerability in index.php in MyBB 1.8.x thr…
- CVE-2018-19203PRTG Network Monitor before 18.2.41.1652 allows remote unaut…
- CVE-2018-19205Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protec…
- CVE-2018-19206steps/mail/func.inc in Roundcube before 1.3.8 has XSS via cr…
- CVE-2018-19207The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plug…
- CVE-2018-19208In libwpd 0.10.2, there is a NULL pointer dereference in the…6.5
- CVE-2018-19209Netwide Assembler (NASM) 2.14rc15 has a NULL pointer derefer…
- CVE-2018-1921IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to c…5.4
Are you affected by CVE-2018-19204?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
