ZeroHour

CVE-2024-46909

large

Unauthenticated RCE in Progress WhatsUp Gold (< 2024.0.1)

CVSS 3.1
9.8 critical
EPSS
49%p99
Published
()
Modified
AI analysis

Progress WhatsUp Gold releases before 2024.0.1 contain a critical vulnerability that allows a remote, unauthenticated attacker to execute code in the context of the WhatsUp Gold service account; the associated weaknesses (CWE-16 configuration, CWE-22 path traversal, CWE-73 externally controlled file path) point to a file-path handling flaw. It is triggered over the network with no credentials, no special conditions, and no user interaction, which is why it scores 9.8 (critical) on CVSS 3.1. Successful exploitation gives an attacker code execution as the service account, which typically runs with high local privileges on the monitoring server and often holds credentials for the devices and networks being monitored. All deployments running any WhatsUp Gold version prior to 2024.0.1 are affected. No public proof-of-concept or CISA KEV listing is known, but the elevated EPSS score (48.9% probability of exploitation within 30 days, 99th percentile) suggests exploitation attempts are likely soon.

What to do: Upgrade to WhatsUp Gold 2024.0.1 or later, which the vendor shipped alongside several other WhatsUp Gold fixes. If upgrading is delayed, restrict access to the WhatsUp Gold web interface to trusted management networks and review the privileges of the account under which the service runs. Because these servers frequently store credentials for monitored devices, treat them as high-value and check for indicators of compromise.

Affected
Progress WhatsUp Goldall versions released before 2024.0.1
Estimated exposure
largetens of thousands of on-prem deployments, of which likely only a few thousand are directly internet-exposed — WhatsUp Gold is a long-established on-premises network monitoring platform whose install base across mid-size enterprises and MSPs is generally estimated in the tens of thousands of deployments, while public internet scans of its web…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.

Vendors
progress
Products
whatsup gold
Weakness
CWE-16, CWE-22, CWE-73
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news