CRITICAL🇵🇱 Wersja polska

CVE-2024-12106

CVSS 9.4v3.1pub. 2024-12-31upd. 2025-01-06

In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.

🤖 AI Analysis
How it works

The vulnerability results from a lack of authentication mechanism (CWE-306) protecting the endpoint responsible for LDAP configuration. An attacker, without possessing any credentials, can send a network request directly to the application and overwrite LDAP directory integration settings. This allows redirecting the user authentication process to an attacker-controlled LDAP server.

Impact

An attacker can take control of the application user authentication process, which in practice can lead to credential interception or unauthorized access to the WhatsUp Gold network monitoring system with high privileges.

Mitigation & patch

Progress WhatsUp Gold must be updated immediately to version 2024.0.2 or newer. Additional information is available in the vendor references at https://www.progress.com/network-monitoring

Who is affected

Progress WhatsUp Gold — all versions released before 2024.0.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
  • Progress Whatsup Gold

    APP
    Progress
    23.1.0 – 24.0.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-6670CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection w Progress WhatsUp Gold — kradzież zaszyfrowanych haseł

CVE-2024-4885CRITICAL9.8⚠ KEVPL ✓same product

Progress WhatsUp Gold – nieuwierzytelniony RCE przez path traversal

CVE-2024-12108CRITICAL9.6PL ✓same product

Progress WhatsUp Gold — nieautoryzowany dostęp do serwera przez publiczne API

CVE-2024-46909CRITICAL9.8PL ✓same product

Zdalne wykonanie kodu w Progress WhatsUp Gold (RCE bez uwierzytelnienia)

CVE-2024-8785CRITICAL9.8PL ✓same product

Progress WhatsUp Gold – nieautoryzowana modyfikacja rejestru Windows przez NmAPI.exe