Monitoring platforms are web applications with two properties that make them prime targets: they store credentials to reach every monitored system (device logins, SNMP strings, database and cloud secrets), and many of them run commands on monitored hosts as a feature. The attack flow is the same across products: fingerprint and enumerate the version, gain access through default or weak credentials or an authentication bypass, then either execute code (through the platform's own command/script features or a known vulnerability) or harvest the stored credentials. Any of these converts a single platform compromise into broad reach across the environment.
Subtopics#
- Zabbix: items, scripts, the agent, and known server bugs.
- Nagios and Icinga: NRPE, command injection, and Nagios XI chains.
- PRTG Network Monitor: notification-based code execution.
- Cacti: the recurring SQLi and command-injection RCE.
- LibreNMS and Observium: command injection and stored credentials.
- Grafana: path traversal, data-source SSRF, and stored credentials.
- Prometheus: exposed interfaces, SSRF, and exporter abuse.
- SolarWinds Orion: stored credentials and known RCE chains.