PatchSiren cyber security CVE debrief
CVE-2018-19410 Paessler CVE debrief
CVE-2018-19410 is a local file inclusion issue in Paessler PRTG Network Monitor that CISA added to the Known Exploited Vulnerabilities catalog on 2025-02-04. Because it is KEV-listed, defenders should treat it as a known-exploited risk rather than a historical record only. CISA’s guidance in the source corpus is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable.
- Vendor
- Paessler
- Product
- PRTG Network Monitor
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2025-02-04
- Original CVE updated
- 2025-02-04
- Advisory published
- 2025-02-04
- Advisory updated
- 2025-02-04
Who should care
Organizations that run Paessler PRTG Network Monitor, along with vulnerability management, patching, and incident response teams responsible for that product.
Technical summary
The supplied official record identifies the issue as a local file inclusion vulnerability in Paessler PRTG Network Monitor. CISA’s KEV entry marks it as known exploited, with a due date of 2025-02-25 for remediation actions. The corpus does not provide CVSS scoring or additional exploit details, so defensive action should be driven by the KEV listing and vendor guidance referenced by CISA.
Defensive priority
Immediate priority for affected deployments because the issue is listed in CISA’s Known Exploited Vulnerabilities catalog.
Recommended defensive actions
- Inventory all Paessler PRTG Network Monitor installations and confirm whether any are affected.
- Apply vendor mitigations referenced by CISA and Paessler as soon as possible.
- If mitigations are unavailable or ineffective, discontinue use of the product per CISA guidance.
- Track remediation against the CISA KEV due date of 2025-02-25.
- Include this CVE in vulnerability management and incident response monitoring because KEV listing indicates known exploitation.
Evidence notes
CISA’s KEV source metadata names the vulnerability as a Paessler PRTG Network Monitor local file inclusion issue, with dateAdded 2025-02-04, dueDate 2025-02-25, and requiredAction instructing organizations to apply vendor mitigations or discontinue use if mitigations are unavailable. The same source notes reference the Paessler product history page and the NVD detail page. The supplied corpus does not include a CVSS score.
Sources and references
Verified primary and authoritative sources
-
CVE-2018-19410 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2018-19410
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2018-19410 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2018-19410
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.