CVE-2024-12105
largeAuthenticated path traversal in Progress WhatsUp Gold versions before 2024.0.2
Progress WhatsUp Gold versions released before 2024.0.2 contain an information-disclosure flaw classified as CWE-22 (path traversal), in which an authenticated user can send a specially crafted HTTP request to access resources outside the intended directory. The issue is reachable over the network with low privileges and no user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N). A successful exploit yields a high confidentiality impact — the attacker can read sensitive data or files accessible to the application — with no integrity or availability impact. Any organization running an affected WhatsUp Gold release is exposed, especially where the web interface is reachable by accounts an attacker could obtain or compromise. No public proof of concept or CISA KEV listing exists yet, but the EPSS score of 42.4% (99th percentile) suggests a substantial probability of exploitation within 30 days.
What to do: Upgrade to WhatsUp Gold 2024.0.2 or later. In the interim, inventory and restrict WhatsUp Gold web interfaces to trusted networks, and review or rotate low-privileged accounts that could be used to send the crafted request. Given the elevated EPSS (42.4%, 99th percentile), prioritize patching even though no public PoC or confirmed in-the-wild exploitation is currently known.
| Progress WhatsUp Gold | all versions released before 2024.0.2 (fixed in 2024.0.2) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.
- Vendors
- progress
- Products
- whatsup gold
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N