VYPR

Whatsup Gold

by Progress (organisation)

CVEs (62)

  • CVE-2024-6670CriKEVAug 29, 2024
    risk 0.92cvss 9.8epss 0.95

    In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

  • CVE-2024-4885CriKEVJun 25, 2024
    risk 0.84cvss 9.8epss 0.99

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.

  • CVE-2024-4883CriJun 25, 2024
    risk 0.69cvss 9.8epss 0.65

    In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.

  • CVE-2024-46909CriDec 2, 2024
    risk 0.68cvss 9.8epss 0.49

    In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.

  • CVE-2015-8261CriJan 8, 2016
    risk 0.67cvss 9.8epss 0.04

    The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.

  • CVE-2024-4884CriJun 25, 2024
    risk 0.66cvss 9.8epss 0.24

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileges.

  • CVE-2024-6671CriAug 29, 2024
    risk 0.65cvss 9.8epss 0.15

    In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

  • CVE-2024-8785CriDec 2, 2024
    risk 0.64cvss 9.8epss 0.10

    In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.

  • CVE-2024-7763CriOct 24, 2024
    risk 0.64cvss 9.8epss 0.01

    In WhatsUp Gold versions released before 2024.0.0,  an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.

  • CVE-2018-8939CriMay 1, 2018
    risk 0.64cvss 9.8epss 0.01

    An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the NmAPI executable to (1) gain unauthorized access to the WhatsUp Gold system, (2) obtain information about the WhatsUp Gold…

  • CVE-2018-8938CriMay 1, 2018
    risk 0.64cvss 9.8epss 0.02

    A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially crafted SNMP MIB file that could allow them to execute arbitrary commands and code on the WhatsUp Gold server.

  • CVE-2018-5778CriJan 24, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Multiple SQL injection vulnerabilities are present in the legacy .ASP pages, which could allow attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2018-5777CriJan 24, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a misconfiguration in the TFTP server that could allow attackers to execute arbitrary commands on the TFTP server via unspecified vectors.

  • CVE-2024-12108CriDec 31, 2024
    risk 0.63cvss 9.6epss 0.07

    In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.

  • CVE-2024-12106CriDec 31, 2024
    risk 0.62cvss 9.4epss 0.10

    In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.

  • CVE-2022-42711CriOct 12, 2022
    risk 0.62cvss 9.6epss 0.01

    In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

  • CVE-2024-46906HigDec 2, 2024
    risk 0.60cvss 8.8epss 0.41

    In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.

  • CVE-2024-5008HigJun 25, 2024
    risk 0.59cvss 8.8epss 0.17

    In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using Apm.UI.Areas.APM.Controllers.Api.Applications.AppProfileImportController.

  • CVE-2026-65941HigAug 12, 2026
    risk 0.57cvss 8.8epss

    In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

  • CVE-2024-46908HigDec 2, 2024
    risk 0.57cvss 8.8epss 0.02

    In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.

Page 1 of 4