CRITICAL🇵🇱 Wersja polska

CVE-2024-12108

CVSS 9.6v3.1pub. 2024-12-31upd. 2025-01-06

In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-290 (Authentication Bypass by Spoofing) allows an attacker to bypass authentication or authorization mechanisms through the WhatsUp Gold public API. An attacker with basic network access (PR:L) can, without user interaction, submit crafted requests to the API, which are accepted by the server despite lacking appropriate permissions. The spoofing defense mechanism is ineffective, enabling takeover of the server context.

Impact

An attacker can gain unauthorized access to the WhatsUp Gold server, risking disclosure of sensitive configuration data and network monitoring data (C:H) as well as modification of system data or configuration (I:H). The scope of the attack extends beyond the directly vulnerable component (S:C), which may lead to further lateral movement in the infrastructure.

Mitigation & patch

Progress WhatsUp Gold must be updated immediately to version 2024.0.2 or newer. Detailed information about the patch is available at https://www.progress.com/network-monitoring. Until the update is applied, it is recommended to restrict access to the public API to trusted IP addresses only through firewall rules.

Who is affected

Progress WhatsUp Gold in all versions released before 2024.0.2, running on the Microsoft Windows platform

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Microsoft Windows

    OS
    Microsoft
    all versions
  • Progress Whatsup Gold

    APP
    Progress
    23.1.0 – 24.0.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2024-6670CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection w Progress WhatsUp Gold — kradzież zaszyfrowanych haseł

CVE-2024-7262CRITICAL9.3⚠ KEVPL ✓same product

Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows