← Vulnerability feed

Vulnerability record · CVE-2023-32782 · published 9 August 2023

CVE-2023-32782: PRTG Network Monitor DICOM C-ECHO sensor command injection

Paessler · Prtg Network Monitor

PRTG Network Monitor 23.2.84.1566 and earlier contains a command injection flaw in the DICOM C-ECHO sensor. An authenticated user with write permissions can abuse the debug option to write files that may later be executed by the EXE/Script sensor, turning a monitoring feature into a code execution path.

7.2 CVSS 3.1 High EPSS 56% · top 1.0% CWE-77 · Command injection
7.2CVSS 3.1 base score
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity of this vulnerability is high and received a score of 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 7.2 with high confidentiality, integrity and availability impact and a 99th percentile EPSS score, though exploitation requires authenticated write access.

What it is

PRTG Network Monitor 23.2.84.1566 and earlier contains a command injection flaw in the DICOM C-ECHO sensor. An authenticated user with write permissions can abuse the debug option to write files that may later be executed by the EXE/Script sensor, turning a monitoring feature into a code execution path.

Impact

An attacker with the required write permissions can write arbitrary files and potentially achieve code execution on the PRTG server, compromising confidentiality, integrity and availability of the host and monitored environment.

Attack surface

Reachable over the network through the PRTG web interface; exploitation requires an authenticated account with write permissions and no user interaction. The CVSS vector confirms network access, low complexity and high privileges.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware association is recorded, but EPSS is 0.56159 (99th percentile), indicating a high predicted likelihood of exploitation activity.

What to do

  • Upgrade PRTG Network Monitor to 23.3.86.1520 or later as directed by the vendor advisory.
  • Restrict write permissions and sensor creation rights to the minimum set of trusted administrators.
  • Disable or tightly control the debug option on DICOM C-ECHO sensors where it is not required.
  • Review EXE/Script sensor configurations and script directories for unexpected or attacker-written files.
  • Monitor and alert on new file creation in PRTG script and sensor execution paths.

Detection

  • Audit PRTG logs for DICOM C-ECHO sensor debug option changes and unusual sensor configuration edits.
  • Monitor the PRTG script and EXE/Script sensor directories for newly created or modified files.
  • Alert on unexpected child processes spawned by PRTG sensor or script execution.
  • Correlate PRTG administrative account activity with file writes and process creation on the PRTG host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-32782 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-19410PRTG Network Monitor unauthenticated local file inclusion enables admin user creationPRTG Network Monitor before 18.2.40.1683 lets an unauthenticated remote attacker abuse the 'include' directive in /public/login.htm to perform local …KEVEPSS 98%analysed7.2CVE-2018-9276PRTG Network Monitor OS Command Injection via Malformed ParametersPRTG Network Monitor before 18.2.39 contains an OS command injection flaw (CWE-78) reachable through malformed parameters in sensor or notification m…KEVEPSS 87%analysed9.8CVE-2020-10374Paessler prtg network monitor improper input validation vulnerabilityA webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST req…EPSS 4.7%8.8CVE-2023-31452Paessler prtg network monitor cross-site request forgery vulnerabilityA cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform act…EPSS 0.65%8.8CVE-2018-19411Paessler prtg network monitor improper privilege management vulnerabilityPRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user with a read-write account (incl…EPSS 0.87%8.8CVE-2018-19204Paessler prtg network monitor improper input validation vulnerabilityPRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS command…EPSS 4.6%7.5CVE-2018-19203Paessler prtg network monitor vulnerabilityPRTG Network Monitor before 18.2.41.1652 allows remote unauthenticated attackers to terminate the PRTG Core Server Service via a special HTTP request.EPSS 2.8%7.5CVE-2018-10253Paessler prtg network monitor memory buffer overflow vulnerabilityPaessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.EPSS 7.4%

Source: NIST National Vulnerability Database (record CVE-2023-32782), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.