CVE-2023-22631
A NVD · · CVE-2023-22631
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key metrics
- CVSS
- 2.7
- EPSS
- 0%
Key insight
Beyond the plain patch information, the report adds no new insight: there is no indication of active exploitation, nor any details on TTPs or affected sectors.
Description
CVE-2023-22631 affects PRTG Network Monitor in versions before 23.1.82. Via the HTTP XML/REST sensor, remote attackers can write files on the system. The vulnerability was fixed by vendor Paessler in release 23.1.82. At the time of the NVD publication there were no indications of active exploitation, no exploit code, and no inclusion in the CISA KEV list. Attacks require access to the web interface or the REST endpoint of the monitoring server.
Risk score
- cvss base
- 27.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 27.00
- industry weight
- 1.10
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational