WhatsUp Gold InstallController Denial-of-Service Vulnerability
Published Jun 25, 2024
7.5
HIGHCVSS 3.1
EPSS 0.85%
Description
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service
vulnerability was identified. An unauthenticated attacker can put the application into the SetAdminPassword installation step, which renders the application non-accessible.
Affected products
-
Affected
- ≥ 2023.1.0, < 2023.1.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Progress Software Corporation | WhatsUp Gold | affected | Affected
|
- < 23.1.3
-
Affected
- ≥ 2023.1.0, < 2023.1.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Progress | Whatsup Gold | affected | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024 vendor-advisoryVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-46285 Advisory
- https://www.progress.com/network-monitoring product
| Link | Providers | Tags |
|---|---|---|
| https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024 | vendor-advisoryVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-46285 | Advisory | |
| https://www.progress.com/network-monitoring | product |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
ENISA EUVD
GitHub
No data