Paessler develops a focused portfolio of network and infrastructure monitoring appliances, with its flagship PRTG Network Monitor product serving as a central visibility and alerting platform in managed IT environments. The vendor's vulnerability profile clusters around web-application and input-handling issues—cross-site scripting, path traversal, improper input validation, and cross-site request forgery—reflecting the web-facing nature of its monitoring dashboards and configuration interfaces. Public exploit code has frequently been made available for this vendor's disclosures, consistent with the appeal of monitoring systems as targets for reconnaissance and lateral movement. Defenders should treat updates to these monitoring platforms as operationally urgent, since compromise can enable broad visibility into the monitored infrastructure; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Paessler over time
Signals from CVEs in this vendor scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19410CRITICAL PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user | Nov 21, 2018 | 9.8 | 97 | YES | YES |
CVE-2018-9276HIGH An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit a | Jul 2, 2018 | 7.2 | 97 | YES | YES |
CVE-2023-32782HIGH A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permissions could abuse the debug opt | Aug 9, 2023 | 7.2 | 50 | NO | NO |
CVE-2020-11547MEDIUM PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version | Apr 5, 2020 | 5.3 | 50 | NO | YES |
CVE-2023-32781HIGH A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debu | Aug 9, 2023 | 7.2 | 33 | NO | YES |
CVE-2020-14073MEDIUM XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen | Jun 23, 2020 | 5.4 | 31 | NO | YES |
CVE-2020-10374CRITICAL A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of t | Mar 30, 2020 | 9.8 | 31 | NO | NO |
CVE-2018-10253HIGH Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls. | Apr 21, 2018 | 7.5 | 31 | NO | YES |
CVE-2018-19204HIGH PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with system privileges. When | Nov 12, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-19411HIGH PRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user with a read-write account (including administrator) via an HTT | Nov 21, 2018 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (41 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paessler.
Media articles that mention a CVE ID that affects a product developed by Paessler — matched by CVE ID, not by vendor name.