Learn about CVE-2020-11547 affecting PRTG Network Monitor. Discover how unauthenticated attackers can access sensitive server information. Find mitigation steps here.
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain sensitive information about the server and probes.
Understanding CVE-2020-11547
This CVE involves a vulnerability in PRTG Network Monitor that enables attackers to gather server and probe information without authentication.
What is CVE-2020-11547?
The vulnerability in PRTG Network Monitor allows remote unauthenticated attackers to access details about probes running on the server and the server itself through specific HTTP requests.
The Impact of CVE-2020-11547
This vulnerability can lead to unauthorized access to sensitive information such as CPU usage, memory, Windows version, and internal statistics, posing a risk to the confidentiality and integrity of the system.
Technical Details of CVE-2020-11547
PRTG Network Monitor before version 20.1.57.1745 is affected by this vulnerability.
Vulnerability Description
Attackers can exploit this issue by sending HTTP requests with specific parameters to endpoints like login.htm or index.htm, allowing them to gather sensitive system information.
Affected Systems and Versions
Exploitation Mechanism
Attackers can exploit this vulnerability by sending HTTP requests with specific parameters, such as type=probes, to the login.htm or index.htm endpoints.
Mitigation and Prevention
To address CVE-2020-11547, immediate actions and long-term security practices are recommended.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates