Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability exists within PRTG Network Monitor that could allow unauthorized access. An attacker can exploit this flaw to create new user accounts with administrative capabilities. This could lead to a significant compromise of the monitored network environment, impacting data integrity and system control.
- Vulnerable: PRTG Network Monitor
- Flaw: Allows unauthenticated user creation
- Impact: Unauthorized administrative access
Attack Path
How an attacker could exploit the issue
A remote, unauthenticated attacker can leverage this vulnerability to gain administrative access to the PRTG Network Monitor. The attack involves crafting a specific HTTP request that exploits a local file inclusion flaw. By manipulating this request, an attacker can initiate the creation of a new user account with full read-write privileges, effectively bypassing authentication and gaining control of the system. This could lead to unauthorized access to sensitive network monitoring data and potential manipulation of monitoring configurations.
- The system is exposed to the network.
- Attacker sends a crafted HTTP request.
- Attacker creates an administrator user.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability allows unauthenticated attackers to gain administrative access to the affected system by exploiting a local file inclusion flaw. Attackers can craft specific HTTP requests to create new user accounts with full read-write privileges. This could lead to unauthorized data access, system modification, or complete system compromise.
- Likely attacker skill level: Low
- Required access or conditions: Network access
- Business risk or urgency: Critical
Priority actions
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability allows unauthenticated attackers to create administrator accounts by exploiting a local file inclusion flaw in PRTG Network Monitor. This could lead to unauthorized access and control of the network monitoring system. The risk is amplified as the vulnerability has been observed in the wild and has a high exploitability score.
- Find all PRTG Network Monitor assets.
- Isolate affected systems from the network.
- Update PRTG Network Monitor and verify.
- Monitor system logs for suspicious activity.