In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.
The vulnerability results from a lack of authentication mechanism (CWE-306) protecting the endpoint responsible for LDAP configuration. An attacker, without possessing any credentials, can send a network request directly to the application and overwrite LDAP directory integration settings. This allows redirecting the user authentication process to an attacker-controlled LDAP server.
An attacker can take control of the application user authentication process, which in practice can lead to credential interception or unauthorized access to the WhatsUp Gold network monitoring system with high privileges.
Progress WhatsUp Gold must be updated immediately to version 2024.0.2 or newer. Additional information is available in the vendor references at https://www.progress.com/network-monitoring
Progress WhatsUp Gold — all versions released before 2024.0.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LProgress Whatsup Gold
APPProgress23.1.0 – 24.0.2 (excl.)
Related vulnerabilities
SQL Injection w Progress WhatsUp Gold — kradzież zaszyfrowanych haseł
Progress WhatsUp Gold – nieuwierzytelniony RCE przez path traversal
Progress WhatsUp Gold — nieautoryzowany dostęp do serwera przez publiczne API
Zdalne wykonanie kodu w Progress WhatsUp Gold (RCE bez uwierzytelnienia)
Progress WhatsUp Gold – nieautoryzowana modyfikacja rejestru Windows przez NmAPI.exe