Vulnerability record · CVE-2023-32782 · published 9 August 2023
CVE-2023-32782: PRTG Network Monitor DICOM C-ECHO sensor command injection
Paessler · Prtg Network Monitor
PRTG Network Monitor 23.2.84.1566 and earlier contains a command injection flaw in the DICOM C-ECHO sensor. An authenticated user with write permissions can abuse the debug option to write files that may later be executed by the EXE/Script sensor, turning a monitoring feature into a code execution path.
Description
A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity of this vulnerability is high and received a score of 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 with high confidentiality, integrity and availability impact and a 99th percentile EPSS score, though exploitation requires authenticated write access.
What it is
PRTG Network Monitor 23.2.84.1566 and earlier contains a command injection flaw in the DICOM C-ECHO sensor. An authenticated user with write permissions can abuse the debug option to write files that may later be executed by the EXE/Script sensor, turning a monitoring feature into a code execution path.
Impact
An attacker with the required write permissions can write arbitrary files and potentially achieve code execution on the PRTG server, compromising confidentiality, integrity and availability of the host and monitored environment.
Attack surface
Reachable over the network through the PRTG web interface; exploitation requires an authenticated account with write permissions and no user interaction. The CVSS vector confirms network access, low complexity and high privileges.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware association is recorded, but EPSS is 0.56159 (99th percentile), indicating a high predicted likelihood of exploitation activity.
What to do
- Upgrade PRTG Network Monitor to 23.3.86.1520 or later as directed by the vendor advisory.
- Restrict write permissions and sensor creation rights to the minimum set of trusted administrators.
- Disable or tightly control the debug option on DICOM C-ECHO sensors where it is not required.
- Review EXE/Script sensor configurations and script directories for unexpected or attacker-written files.
- Monitor and alert on new file creation in PRTG script and sensor execution paths.
Detection
- Audit PRTG logs for DICOM C-ECHO sensor debug option changes and unusual sensor configuration edits.
- Monitor the PRTG script and EXE/Script sensor directories for newly created or modified files.
- Alert on unexpected child processes spawned by PRTG sensor or script execution.
- Correlate PRTG administrative account activity with file writes and process creation on the PRTG host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-32782 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-32782), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.