PatchSiren

Paessler CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Paessler CVE published 2026-09-14

CVE-2023-45858

A directory traversal vulnerability was identified in Paessler PRTG before 23.4.88.1429, allowing for the reading of local files. This issue is considered high severity with a CVSS score of 8.6. The vulnerability enables an attacker to read local files, potentially leading to unauthorized access. Defenders responsible for Paessler PRTG systems should assess exposure and prioritize patching to prevent pote [truncated]

HIGH Paessler CVE published 2026-09-14

CVE-2023-28148

Paessler PRTG Network Monitor is vulnerable to a bodyclass XSS issue before version 23.3.86.1520. This vulnerability affects the PRTG Network Monitor, a widely used network monitoring tool. The bodyclass XSS issue allows attackers to inject malicious scripts into the application, potentially leading to unauthorized actions or data breaches. Defenders should assess exposure and apply the vendor-provided pa [truncated]

LOW Paessler CVE published 2026-09-14

CVE-2023-22632

Paessler PRTG Network Monitor versions before 23.1.82 contain a vulnerability allowing remote attackers to write to files via the FTP Server Count Sensor. The CVSS score is 2.7, indicating low severity. The CVE was published on 2026-09-14T04:16:34.960Z and last modified on 2026-09-22T19:56:19.073Z. Defenders responsible for Paessler PRTG Network Monitor deployments should assess exposure and verify the ne [truncated]

LOW Paessler CVE published 2026-09-14

CVE-2023-22631

Paessler PRTG Network Monitor vulnerability allows remote file write via HTTP XML/REST Sensor. This low-severity vulnerability, with a CVSS score of 2.7, enables attackers to write files on affected systems, potentially leading to unauthorized modifications or data breaches. Defenders should verify and apply vendor remediation if available, restrict access to the sensor, and monitor for suspicious activit [truncated]

Known exploited Paessler CVE published 2025-02-04

CVE-2018-9276

CVE-2018-9276 is an OS command injection issue associated with Paessler PRTG Network Monitor and is included in CISA’s Known Exploited Vulnerabilities catalog. The supplied record does not include a CVSS score or detailed version guidance, but the KEV listing means defenders should treat it as an urgent exposure. CISA’s note directs organizations to apply vendor mitigations or discontinue use of the produ [truncated]

Known exploited Paessler CVE published 2025-02-04

CVE-2018-19410

CVE-2018-19410 is a local file inclusion issue in Paessler PRTG Network Monitor that CISA added to the Known Exploited Vulnerabilities catalog on 2025-02-04. Because it is KEV-listed, defenders should treat it as a known-exploited risk rather than a historical record only. CISA’s guidance in the source corpus is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

MEDIUM Paessler CVE published 2017-01-23

CVE-2015-7743

CVE-2015-7743 is an XML external entity (XXE) issue in Paessler PRTG Network Monitor. Per the CVE description in the supplied corpus, a remote authenticated user could create a new HTTP XML/REST Value sensor that processes a crafted XML file and read arbitrary files. The NVD record maps the weakness to CWE-611 and describes a network-reachable issue that requires low privileges but no user interaction. Pa [truncated]