CVE-2021-27220

An issue was discovered in PRTG Network Monitor before 21.1.66.1623. By invoking the screenshot functionality with prepared context paths, an attacker is able to verify the existence of certain files on the filesystem of the PRTG's Web server.
References
Link Resource
https://www.paessler.com/prtg/history/stable#21.1.66.1623 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:paessler:prtg_network_monitor:*:*:*:*:*:*:*:*

History

06 Apr 2021, 15:48

Type Values Removed Values Added
References (CONFIRM) https://www.paessler.com/prtg/history/stable#21.1.66.1623 - (CONFIRM) https://www.paessler.com/prtg/history/stable#21.1.66.1623 - Release Notes, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 5.3
CPE cpe:2.3:a:paessler:prtg_network_monitor:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

31 Mar 2021, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-03-31 22:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-27220

Mitre link : CVE-2021-27220

CVE.ORG link : CVE-2021-27220


JSON object : View

Products Affected

paessler

  • prtg_network_monitor