PT-2025-45113 · Dynatrace · Dynatrace Activegate

CVE-2025-61304

·

Published

2025-11-05

·

Updated

2025-11-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dynatrace ActiveGate versions up to 1.016
Description An OS command injection issue exists in the Dynatrace ActiveGate ping extension. This flaw allows for potential code execution through the use of specially crafted IP addresses. The ping extension is susceptible to this issue, potentially enabling an attacker to inject and execute arbitrary operating system commands. The vulnerable component processes IP addresses without sufficient validation, leading to the possibility of command injection. The affected parameter is the IP address provided to the ping extension.
Recommendations Update Dynatrace ActiveGate to a version beyond 1.016.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61304

Affected Products

Dynatrace Activegate