Progress Whatsup Gold vulnerabilities
56 known vulnerabilities affecting progress/whatsup_gold.
Total CVEs
56
CISA KEV
2
actively exploited
Public exploits
12
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH22MEDIUM21
Vulnerabilities
Page 1 of 3
CVE-2024-4885P1CRITICALCVSS 9.8KEVPoCfixed in 23.1.32024-06-25
CVE-2024-4885 [CRITICAL] CWE-22 CVE-2024-4885: In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerab
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The
WhatsUp.ExportUtilities.Export.GetFileWithoutZip
allows execution of commands with iisapppool\nmconsole privileges.
nvd
CVE-2024-6670P1CRITICALCVSS 9.8KEVPoCRansomwarefixed in 24.02024-08-29
CVE-2024-6670 [CRITICAL] CWE-89 CVE-2024-6670: In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthent
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
nvd
CVE-2024-6671P1CRITICALCVSS 9.8ExploitedPoC≥ 23.1.0, < 24.02024-08-29
CVE-2024-6671 [CRITICAL] CWE-89 CVE-2024-6671: In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a sing
In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
nvd
CVE-2022-29847P2HIGHCVSS 7.5PoC≥ 21.0.0, ≤ 21.1.1v22.0.02022-05-11
CVE-2022-29847 [HIGH] CWE-918 CVE-2022-29847: In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthent
In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host.
nvd
CVE-2024-4883P1CRITICALCVSS 9.8fixed in 23.1.32024-06-25
CVE-2024-4883 [CRITICAL] CWE-77 CVE-2024-4883: In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress
In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.
nvd
CVE-2024-46909P1CRITICALCVSS 9.8fixed in 24.0.12024-12-02
CVE-2024-46909 [CRITICAL] CWE-16 CVE-2024-46909: In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
nvd
CVE-2015-8261P2CRITICALCVSS 9.8PoCv16.32016-01-08
CVE-2015-8261 [CRITICAL] CWE-89 CVE-2015-8261: The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.
nvd
CVE-2024-4884P1CRITICALCVSS 9.8fixed in 23.1.32024-06-25
CVE-2024-4884 [CRITICAL] CWE-77 CVE-2024-4884: In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerab
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The Apm.UI.Areas.APM.Controllers.CommunityController
allows execution of commands with iisapppool\nmconsole privileges.
nvd
CVE-2004-0798P3HIGHCVSS 7.5PoCv7.0v7.03+4 more2004-10-20
CVE-2004-0798 [HIGH] CVE-2004-0798: Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter.
nvd
CVE-2024-46906P2HIGHCVSS 8.8fixed in 24.0.12024-12-02
CVE-2024-46906 [HIGH] CWE-89 CVE-2024-46906: In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authentic
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
nvd
CVE-2024-5010P2HIGHCVSS 7.5fixed in 23.1.32024-06-25
CVE-2024-5010 [HIGH] CWE-200 CVE-2024-5010: In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController func
In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality. A specially crafted
unauthenticated
HTTP request can lead to a disclosure of sensitive information.
nvd
CVE-2012-2601P3HIGHCVSS 7.5PoCv15.022012-08-15
CVE-2012-2601 [HIGH] CWE-89 CVE-2012-2601: SQL injection vulnerability in WrVMwareHostList.asp in Ipswitch WhatsUp Gold 15.02 allows remote att
SQL injection vulnerability in WrVMwareHostList.asp in Ipswitch WhatsUp Gold 15.02 allows remote attackers to execute arbitrary SQL commands via the sGroupList parameter.
nvd
CVE-2024-5008P2HIGHCVSS 8.8fixed in 23.1.32024-06-25
CVE-2024-5008 [HIGH] CWE-434 CVE-2024-5008: In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions
In WhatsUp Gold versions released before 2023.1.3,
an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using Apm.UI.Areas.APM.Controllers.Api.Applications.AppProfileImportController.
nvd
CVE-2024-12108P2CRITICALCVSS 9.6≥ 23.1.0, < 24.0.22024-12-31
CVE-2024-12108 [CRITICAL] CWE-290 CVE-2024-12108: In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold s
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.
nvd
CVE-2022-29848P3MEDIUMCVSS 6.5PoC≥ 17.0.0, ≤ 21.1.1v22.0.02022-05-11
CVE-2022-29848 [MEDIUM] CWE-918 CVE-2022-29848: In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authentic
In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read sensitive operating-system attributes from a host that is accessible by the WhatsUp Gold system.
nvd
CVE-2024-5016P2HIGHCVSS 7.2fixed in 23.1.0v23.1.02024-06-25
CVE-2024-5016 [HIGH] CWE-502 CVE-2024-5016: In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploite
In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as SYSTEM.
The vulnerability exists in the main message processing routines NmDistributed.DistributedServiceBehavior.OnMessage for server and NmDistributed.DistributedClient.OnMessage fo
nvd
CVE-2022-29845P3MEDIUMCVSS 6.5PoCv21.1.0v21.1.1+1 more2022-05-11
CVE-2022-29845 [MEDIUM] CWE-829 CVE-2022-29845: In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authentic
In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read the contents of a local file.
nvd
CVE-2024-5011P3HIGHCVSS 7.5fixed in 23.1.32024-06-25
CVE-2024-5011 [HIGH] CWE-400 CVE-2024-5011: In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerabilit
In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTTP request to the TestController Chart functionality can lead to denial of service.
nvd
CVE-2023-35759P3MEDIUMCVSS 6.1PoCfixed in 23.0.02023-06-23
CVE-2023-35759 [MEDIUM] CWE-79 CVE-2023-35759: In Progress WhatsUp Gold before 23.0.0, an SNMP-related application endpoint failed to adequately sa
In Progress WhatsUp Gold before 23.0.0, an SNMP-related application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS.
nvd
CVE-2022-29846P3MEDIUMCVSS 5.3PoC≥ 16.1, ≤ 21.1.1v22.0.02022-05-11
CVE-2022-29846 [MEDIUM] CVE-2022-29846: In Progress Ipswitch WhatsUp Gold 16.1 through 21.1.1, and 22.0.0, it is possible for an unauthentic
In Progress Ipswitch WhatsUp Gold 16.1 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to obtain the WhatsUp Gold installation serial number.
nvd
1 / 3Next →