PatchSiren

Paessler CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Paessler CVE published 2025-02-04

CVE-2018-9276

CVE-2018-9276 is an OS command injection issue associated with Paessler PRTG Network Monitor and is included in CISA’s Known Exploited Vulnerabilities catalog. The supplied record does not include a CVSS score or detailed version guidance, but the KEV listing means defenders should treat it as an urgent exposure. CISA’s note directs organizations to apply vendor mitigations or discontinue use of the produ [truncated]

Known exploited Paessler CVE published 2025-02-04

CVE-2018-19410

CVE-2018-19410 is a local file inclusion issue in Paessler PRTG Network Monitor that CISA added to the Known Exploited Vulnerabilities catalog on 2025-02-04. Because it is KEV-listed, defenders should treat it as a known-exploited risk rather than a historical record only. CISA’s guidance in the source corpus is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

MEDIUM Paessler CVE published 2017-01-23

CVE-2015-7743

CVE-2015-7743 is an XML external entity (XXE) issue in Paessler PRTG Network Monitor. Per the CVE description in the supplied corpus, a remote authenticated user could create a new HTTP XML/REST Value sensor that processes a crafted XML file and read arbitrary files. The NVD record maps the weakness to CWE-611 and describes a network-reachable issue that requires low privileges but no user interaction. Pa [truncated]