ZeroHour

CVE-2024-12105

large

Authenticated path traversal in Progress WhatsUp Gold versions before 2024.0.2

CVSS 3.1
6.5 medium
EPSS
42%p99
Published
()
Modified
AI analysis

Progress WhatsUp Gold versions released before 2024.0.2 contain an information-disclosure flaw classified as CWE-22 (path traversal), in which an authenticated user can send a specially crafted HTTP request to access resources outside the intended directory. The issue is reachable over the network with low privileges and no user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N). A successful exploit yields a high confidentiality impact — the attacker can read sensitive data or files accessible to the application — with no integrity or availability impact. Any organization running an affected WhatsUp Gold release is exposed, especially where the web interface is reachable by accounts an attacker could obtain or compromise. No public proof of concept or CISA KEV listing exists yet, but the EPSS score of 42.4% (99th percentile) suggests a substantial probability of exploitation within 30 days.

What to do: Upgrade to WhatsUp Gold 2024.0.2 or later. In the interim, inventory and restrict WhatsUp Gold web interfaces to trusted networks, and review or rotate low-privileged accounts that could be used to send the crafted request. Given the elevated EPSS (42.4%, 99th percentile), prioritize patching even though no public PoC or confirmed in-the-wild exploitation is currently known.

Affected
Progress WhatsUp Goldall versions released before 2024.0.2 (fixed in 2024.0.2)
Estimated exposure
largetens of thousands of WhatsUp Gold deployments worldwide, with on the order of a few thousand instances internet-exposed per public scans (estimate; exact… — WhatsUp Gold is widely deployed as an enterprise network-monitoring platform with a customer base historically described by the vendor in the tens of thousands, and public internet-exposure scans of its web console typically show thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.

Vendors
progress
Products
whatsup gold
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news