CVE-2019-19119
PRTG Network Monitor vulnerability analysis and mitigation

Overview

An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a local user with limited privileges could read the PRTG System Administrator user account's password hash from the Windows registry. This vulnerability was assigned CVE-2019-19119. The issue was discovered by Aleksandr Melkikh from Positive Technologies (PRTG Blog).

Technical details

The vulnerability exists due to default Windows registry permissions that allow local users read access to registry paths used by PRTG. This allows an attacker with local user access to read the PRTG System Administrator password hash. The vulnerability has a CVSS score indicating high severity with the following vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H/E:U/RL:O/RC:C (PRTG Blog).

Impact

The vulnerability allows a local attacker with limited privileges to obtain the password hash of the PRTG System Administrator account, potentially leading to unauthorized access to the PRTG system with administrative privileges (PRTG Blog).

Mitigation and workarounds

The vulnerability was fixed in PRTG version 19.4.54. Users running affected versions should update to version 19.4.54 or later as soon as possible. Paessler sent email notifications to customers running vulnerable versions with detailed information about the vulnerability (PRTG Blog).

Additional resources


SourceThis report was generated using AI

Related PRTG Network Monitor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-31452HIGH8.8
  • PRTG Network MonitorPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesAug 09, 2023
CVE-2023-32782HIGH7.2
  • PRTG Network MonitorPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesAug 09, 2023
CVE-2023-32781HIGH7.2
  • PRTG Network MonitorPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesAug 09, 2023
CVE-2024-12833MEDIUM6.1
  • PRTG Network MonitorPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesFeb 11, 2025
CVE-2023-51630MEDIUM6.1
  • PRTG Network MonitorPRTG Network Monitor
  • cpe:2.3:a:paessler:prtg_network_monitor
NoYesFeb 08, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management