Sceawere

Vulnerability Detail

CVE-2023-22632UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

PRTG FTP Sensor File Write

Vulnerability Metadata

Severity
Low
Score / CVSS
2.7
Creation Date
2h ago
Vendor
Paessler
Product
PRTG Network Monitor
Attack Type
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.7",
  "pubDate": "2026-09-14T04:16:34.960Z",
  "pubdate": "2026-09-14T04:16:34.960Z",
  "executiveSummary": "This vulnerability involves an arbitrary file write flaw within the PRTG Network Monitor FTP Server Count Sensor, affecting all versions prior to 23.1.82.\nThe vulnerability allows an unauthenticated or remote attacker to bypass intended file system restrictions and write data to arbitrary locations on the host server.\nBy leveraging this flaw, a malicious actor can achieve remote code execution, modify system configurations, or compromise sensitive data storage within the PRTG environment.\nThe risk to the organization is critical, as it bypasses standard access control mechanisms and facilitates full system compromise. Successful exploitation requires network-level access to the affected PRTG instance but does not necessarily require authenticated session credentials.\nThe impact is significant, potentially leading to a complete breach of the monitoring server and escalation into the broader production network.",
  "technicalDetails": "The vulnerability resides within the PRTG Network Monitor FTP Server Count Sensor component, which fails to properly sanitize input parameters before performing file operations. The flaw manifests as an improper validation of user-supplied input paths, permitting path traversal or direct file write operations outside of the designated, sandboxed directory.\nIn terms of attack flow, an attacker identifies the FTP Server Count Sensor as a target. Through crafted requests, the attacker injects malicious input that is processed by the underlying application logic. Because the sensor does not adequately restrict the destination of write operations, the application facilitates the creation or overwriting of files within the host filesystem context of the PRTG service.\nThe exploitation method relies on the server-side application processing the malicious input to execute system calls that write data to an unintended location. If the PRTG service is running with elevated privileges—a common configuration for monitoring tools—the impact is amplified, allowing the attacker to overwrite binaries, configuration scripts, or critical system files.\nRegarding payload behavior, an attacker might target specific files such as configuration files (.ini, .conf) to alter the behavior of the application, or executable files if the attacker has sufficient permissions to replace them. By overwriting existing binaries with malicious payloads or inserting arbitrary code into script-based executables, the attacker achieves remote code execution.\nThis vulnerability is classified as an improper input validation issue leading to arbitrary file write. Because the PRTG Network Monitor requires exposure to monitor network assets, the attack surface is inherent to its deployment. The lack of robust input validation mechanisms within the FTP Server Count Sensor allows the application to be tricked into performing write operations it was never intended to support.\nPost-exploitation activity typically includes the establishment of persistence mechanisms, the deployment of web shells to maintain persistent remote access, or the lateral movement from the compromised PRTG server into internal network segments, effectively neutralizing any segmentation previously implemented for the monitoring environment."
}
CVE-2023-22632: PRTG FTP Sensor File Write (LOW Severity, CVSS: 2.7) | Sceawere