Dynatrace ActiveGate Ping Extension OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the Dynatrace ActiveGate ping extension, affecting versions prior to 1.016. This vulnerability allows for OS command injection via a crafted IP address. The ping extension utilizes the Windows command prompt to execute ping commands. The input field for the Test Target Host can accept up to 1024 characters, enabling the injection of additional commands for ActiveGate to execute by appending an '&' after the IP address.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the host where Dynatrace ActiveGate is running.

Reproduction

To reproduce this vulnerability, input a crafted IP address into the Test Target Host field of the Dynatrace ActiveGate ping extension. After the IP address, append additional commands using an '&' to execute arbitrary commands on the Windows command prompt. The ping extension will process the input, leading to command execution on the host.

Remediation

Users are advised to update to Dynatrace ActiveGate ping extension version 1.016 or later.

Added: Nov 5, 2025, 4:17 PM
Updated: Nov 5, 2025, 8:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.7
remediation
0.0
relevance
0.9
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.