CVE-2024-46909
largeUnauthenticated RCE in Progress WhatsUp Gold (< 2024.0.1)
Progress WhatsUp Gold releases before 2024.0.1 contain a critical vulnerability that allows a remote, unauthenticated attacker to execute code in the context of the WhatsUp Gold service account; the associated weaknesses (CWE-16 configuration, CWE-22 path traversal, CWE-73 externally controlled file path) point to a file-path handling flaw. It is triggered over the network with no credentials, no special conditions, and no user interaction, which is why it scores 9.8 (critical) on CVSS 3.1. Successful exploitation gives an attacker code execution as the service account, which typically runs with high local privileges on the monitoring server and often holds credentials for the devices and networks being monitored. All deployments running any WhatsUp Gold version prior to 2024.0.1 are affected. No public proof-of-concept or CISA KEV listing is known, but the elevated EPSS score (48.9% probability of exploitation within 30 days, 99th percentile) suggests exploitation attempts are likely soon.
What to do: Upgrade to WhatsUp Gold 2024.0.1 or later, which the vendor shipped alongside several other WhatsUp Gold fixes. If upgrading is delayed, restrict access to the WhatsUp Gold web interface to trusted management networks and review the privileges of the account under which the service runs. Because these servers frequently store credentials for monitored devices, treat them as high-value and check for indicators of compromise.
| Progress WhatsUp Gold | all versions released before 2024.0.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
- Vendors
- progress
- Products
- whatsup gold
- Weakness
- CWE-16, CWE-22, CWE-73
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H