CRITICAL
WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
Published Jun 25, 2024
9.8
CRITICALCVSS 3.1
EPSS 64.53%
Description
In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.
Affected products
-
- Version 2023.1.0StatusaffectedConstraints<2023.1.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Progress Software Corporation | WhatsUp Gold | affected |
|
- < 23.1.3
-
- Version 2023.1.0StatusaffectedConstraints<2023.1.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Progress | Whatsup Gold | affected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (3)
References (3)
- https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024 vendor-advisoryVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44453 Advisory
- https://www.progress.com/network-monitoring product
| Link | Providers | Tags |
|---|---|---|
| https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024 | vendor-advisoryVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44453 | Advisory | |
| https://www.progress.com/network-monitoring | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ProgressSoftware
Published Jun 25, 2024
Updated Aug 1, 2024
Reserved May 14, 2024
Link CVE-2024-4883
CISA Vulnrichment
Updated Jul 12, 2024
ENISA EUVD
EUVD-2024-44453 Assigner ProgressSoftware
Published Jun 25, 2024
Updated Aug 1, 2024
Exploited since n/a
Link EUVD-2024-44453