CVE-2025-61304: OS Command Injection
Published Nov 5, 2025
·Updated
OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.
Affected Software
2 affected components
Dynatrace ActiveGate ping extension<=1.016
Dynatrace ActiveGate ping extension<=1.016
Event History
Nov 5, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-61304?
CVE-2025-61304 is categorized as a high severity vulnerability due to its potential for OS command injection.
2
How do I fix CVE-2025-61304?
To mitigate CVE-2025-61304, update the Dynatrace ActiveGate ping extension to version 1.017 or later.
3
What components are affected by CVE-2025-61304?
CVE-2025-61304 affects the Dynatrace ActiveGate ping extension versions up to 1.016.
4
What impact does CVE-2025-61304 have on systems?
The impact of CVE-2025-61304 includes the potential for malicious actors to execute arbitrary commands on the affected system.
5
Is CVE-2025-61304 a confirmed vulnerability?
Yes, CVE-2025-61304 has been confirmed and documented as a valid vulnerability by security researchers.