Prtg Network Monitor

Vendor:

First CVE: Jan 23, 2017 · Active for 9 years

39
Total CVEs
More Total CVEs than 98% of tracked products
3.9
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
5.1%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Prtg Network Monitor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2017
9 years ago
Most Recent CVE
Jan 14, 2026
195 days ago

CVE Severity & Scoring

Prtg Network Monitor39 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local2 (5.1%)
Network37 (94.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None22 (56.4%)
Unknown0 (0.0%)
Required17 (43.6%)
Privileges Required
Low10 (25.6%)
High10 (25.6%)
None19 (48.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user
Nov 21, 20189.897YESYES
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit a
Jul 2, 20187.297YESYES
A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permissions could abuse the debug opt
Aug 9, 20237.250NONO
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version
Apr 5, 20205.350NOYES
A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debu
Aug 9, 20237.233NOYES
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen
Jun 23, 20205.431NOYES
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of t
Mar 30, 20209.831NONO
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.
Apr 21, 20187.531NOYES
PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with system privileges. When
Nov 12, 20188.829NONO
PRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user with a read-write account (including administrator) via an HTT
Nov 21, 20188.827NONO

Exploit Exposure

Signals from CVEs in this product scope (39 CVEs).

CISA KEV
2 CVEs
5.1% of CVEs· 98th percentile
Metasploit
2 CVEs
5.1% of CVEs· 97th percentile
Nuclei
2 CVEs
5.1% of CVEs· 97th percentile
ExploitDB
3 CVEs
7.7% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (39 CVEs).

Media Mentions

Signals from CVEs in this product scope (39 CVEs).

Top CNAs Publishing CVEs For Prtg Network Monitor

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.1.3.337826.11.2%00
20.1.56.157415.42.9%01
20.1.55.177514.30.4%00
17.3.33.283055.90.8%00