Paessler PRTG Network Monitor Local File Inclusion Vulnerability
18.2.40.1683 이전 버전의 PRTG Network Monitor에서는 인증되지 않은 원격 공격자가 읽기-쓰기 권한(관리자 포함)을 가진 사용자를 생성할 수 있습니다. 인증되지 않은 원격 사용자는 HTTP 요청을 조작하여 /public/login.htm의 'include' 지시문 속성을 재정의하고, /api/addusers를 포함해 실행함으로써 Local File Inclusion 공격을 수행할 수 있습니다. 인증되지 않은 공격자는 'id' 및 'users' 매개변수를 제공하여 읽기-쓰기 권한(관리자 포함)을 가진 사용자를 생성할 수 있습니다.
18.2.40.1683 이전 버전의 PRTG Network Monitor에서는 인증되지 않은 원격 공격자가 읽기-쓰기 권한(관리자 포함)을 가진 사용자를 생성할 수 있습니다. 인증되지 않은 원격 사용자는 HTTP 요청을 조작하여 /public/login.htm의 'include' 지시문 속성을 재정의하고, /api/addusers를 포함해 실행함으로써 Local File Inclusion 공격을 수행할 수 있습니다. 인증되지 않은 공격자는 'id' 및 'users' 매개변수를 제공하여 읽기-쓰기 권한(관리자 포함)을 가진 사용자를 생성할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator).
영향 제품·버전
제품 Paessler PRTG Network Monitor
영향 버전 Paessler PRTG Network Monitor < 18.2.40.1683
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
조치 기한: 2025.02.25
해당사항 확인방법
Paessler PRTG Network Monitor의 현재 전체 버전이 공식 영향 범위(Paessler PRTG Network Monitor < 18.2.40.1683)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 Paessler PRTG Network Monitor 18.2.40.1683 기준을 충족하는지 확인합니다. 이어서 유형 미확정 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.