CVE-2024-6670
KEV ransomwarelargeUnauthenticated SQL Injection in Progress WhatsUp Gold (CVE-2024-6670)
CISA: Progress WhatsUp Gold SQL Injection Vulnerability
CVE-2024-6670 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) in Progress Software's WhatsUp Gold network monitoring product, affecting all versions released before 2024.0.0. An unauthenticated attacker can trigger the flaw with crafted requests sent to the product over the network, requiring no privileges or user interaction. Successful exploitation lets the attacker retrieve WhatsUp Gold users' encrypted passwords, which can then potentially be cracked offline to gain valid credentials for further compromise. All organizations running affected releases — especially those with the WhatsUp Gold interface reachable beyond trusted internal networks — are exposed, and the flaw is one of two critical WhatsUp Gold issues Progress fixed in the 2024.0.0 release. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-16 with confirmed ransomware use, and EPSS assigns a ~93% probability of exploitation within 30 days, though no public proof-of-concept is catalogued for this flaw.
What to do: Upgrade to WhatsUp Gold 2024.0.0 or later, the release that fixes this flaw; per CISA's KEV requirement, apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Because the flaw exposes encrypted user passwords, reset WhatsUp Gold credentials after patching and review logs for signs of exploitation, given known ransomware use.
| Progress WhatsUp Gold | All versions released before 2024.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
- Affected
- Progress WhatsUp Gold
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- progress
- Products
- whatsup gold
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H