A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2023-45858 is a directory traversal vulnerability in Paessler PRTG Network Monitor versions prior to 23.4.88.1429 that allows attackers to read arbitrary local files on affected systems. Directory traversal vulnerabilities exploit insufficient input validation, permitting attackers to use path manipulation sequences (such as "../" or absolute paths) to escape intended directory boundaries and access sensitive files outside the application's intended scope. This vulnerability matters because PRTG is a widely-deployed network monitoring and management platform used by organizations to monitor infrastructure, meaning compromised instances could expose configuration files, credentials, system information, and other sensitive data. Any organization running vulnerable PRTG versions faces direct risk of information disclosure, particularly if the monitoring platform has access to or knowledge of critical infrastructure details.
While CVE-2023-45858 does not map directly to MITRE ATT&CK techniques in public documentation, Casky's AI-powered analysis would detect the attack patterns associated with this vulnerability by recognizing the underlying adversarial behaviors: initial reconnaissance (T1087 - Account Discovery, T1526 - Cloud Service Discovery) where attackers probe for PRTG instances, followed by exploitation for credential or configuration access (potentially T1110 - Brute Force or T1190 - Exploit Public-Facing Application), and subsequent data exfiltration (T1041 - Exfiltration Over C2 Channel). Practitioners using Casky would see findings highlighting suspicious file path requests containing traversal sequences, anomalous file access patterns from the PRTG application process, and indicators of reconnaissance activity targeting monitoring platforms. Extended reasoning would correlate these signals—such as failed attempts followed by successful file reads—to identify the progression from reconnaissance to exploitation to data access, enabling defenders to intervene before sensitive information reaches attackers.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2023-45858. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation