CVE-2024-12833 HIGH

CVE-2024-12833: Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability

Vendor Paessler
Product PRTG Network Monitor
Weakness CWE-79 · XSS
Published February 11, 2025
Last update February 12, 2025

CVSS base score

8.0/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. Some user interaction on the part of an administrator is required to exploit this vulnerability. The specific flaw exists within the PRTG Network Monitor web interface. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-23371.

Key dates

02Disclosure timeline

February 11, 2025 CVE published
February 12, 2025 Record updated