ZeroHour

CVE-2024-6670

KEV ransomwarelarge

Unauthenticated SQL Injection in Progress WhatsUp Gold (CVE-2024-6670)

CISA: Progress WhatsUp Gold SQL Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
93%p100
Published
()
KEV added
AI analysis

CVE-2024-6670 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) in Progress Software's WhatsUp Gold network monitoring product, affecting all versions released before 2024.0.0. An unauthenticated attacker can trigger the flaw with crafted requests sent to the product over the network, requiring no privileges or user interaction. Successful exploitation lets the attacker retrieve WhatsUp Gold users' encrypted passwords, which can then potentially be cracked offline to gain valid credentials for further compromise. All organizations running affected releases — especially those with the WhatsUp Gold interface reachable beyond trusted internal networks — are exposed, and the flaw is one of two critical WhatsUp Gold issues Progress fixed in the 2024.0.0 release. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-16 with confirmed ransomware use, and EPSS assigns a ~93% probability of exploitation within 30 days, though no public proof-of-concept is catalogued for this flaw.

What to do: Upgrade to WhatsUp Gold 2024.0.0 or later, the release that fixes this flaw; per CISA's KEV requirement, apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Because the flaw exposes encrypted user passwords, reset WhatsUp Gold credentials after patching and review logs for signs of exploitation, given known ransomware use.

Affected
Progress WhatsUp GoldAll versions released before 2024.0.0
Estimated exposure
large≈10,000–100,000 on-prem deployments worldwide (internet-exposed subset likely in the thousands) — No published install counts are provided in the data, so this is an order-of-magnitude estimate based on WhatsUp Gold's long-established deployment pattern as a widely sold on-premises network monitoring platform with an installed base of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

CISA Known Exploited Vulnerability
Affected
Progress WhatsUp Gold
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
progress
Products
whatsup gold
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news