Progress Software Releases Patches for 6 Flaws in WhatsUp Gold
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-46909 | Unauthenticated RCE in Progress WhatsUp Gold (< 2024.0.1) Progress WhatsUp Gold releases before 2024.0.1 contain a critical vulnerability that allows a remote, unauthenticated attacker to execute code in the context of the WhatsUp Gold service account; the associated weaknesses (CWE-16 configuration, CWE-22 path traversal, CWE-73 externally controlled file path) point to a file-path handling flaw. It is triggered over the network with no credentials, no special conditions, and no user interaction, which is why it scores 9.8 (critical) on CVSS 3.1. Successful exploitation gives an attacker code execution as the service account, which typically runs with high local privileges on the monitoring server and often holds credentials for the devices and networks being monitored. All deployments running any WhatsUp Gold version prior to 2024.0.1 are affected. No public proof-of-concept or CISA KEV listing is known, but the elevated EPSS score (48.9% probability of exploitation within 30 days, 99th percentile) suggests exploitation attempts are likely soon. Do: Upgrade to WhatsUp Gold 2024.0.1 or later, which the vendor shipped alongside several other WhatsUp Gold fixes. If upgrading is delayed, restrict access to the WhatsUp Gold web interface to trusted management networks and review the privileges of the account under which the service runs. Because these servers frequently store credentials for monitored devices, treat them as high-value and check for indicators of compromise. | 9.8 group max | 49% |
| largetens of thousands of on-prem deployments, of which likely only a few thousand are directly internet-exposed | ||
| CVE-2024-4885 | Unauthenticated Path Traversal RCE in Progress WhatsUp Gold CVE-2024-4885 is an unauthenticated path traversal vulnerability (CWE-22) in the WhatsUp.ExportUtilities.Export.GetFileWithoutZip function of Progress WhatsUp Gold, a network monitoring platform. An attacker can send a crafted request to the affected export/file-retrieval functionality to traverse outside the intended directory, which leads to execution of commands on the server. Successful exploitation yields remote code execution running with the privileges of the iisapppool\mconsole application pool identity, giving control of the WhatsUp Gold monitoring server and, potentially, a foothold in the network. All WhatsUp Gold versions released before 2023.1.3 are affected, meaning any organization running an unpatched on-premises deployment is exposed, especially if the web interface is reachable from untrusted networks. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-03, and its 99.3% EPSS probability reflects very high expected exploitation; no public PoC is known, though headlines indicate exploitation followed shortly after a proof-of-concept for this WhatsUp Gold flaw. Do: Upgrade WhatsUp Gold to version 2023.1.3 or later, per Progress's advisories (which shipped patches for this and several related WhatsUp Gold flaws). Until patched, restrict access to the WhatsUp Gold web interface to trusted networks and review logs for unexpected requests to the export utility; federal agencies must apply vendor mitigations or follow BOD 22-01 guidance by the KEV due date. Because the flaw is unauthenticated and exploited in the wild, treat any internet-facing, unpatched instance as compromised until verified. | 9.8 | 99% | KEV |
| moderatelow thousands of internet-exposed WhatsUp Gold servers; total on-prem deployments plausibly in the tens of thousands |
Full article313 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 27, 2024Software Security / Vulnerability
Progress Software has released another round of updates to address six security flaws in WhatsUp Gold, including two critical vulnerabilities.
The issues, the company said, have been resolved in version 24.0.1 released on September 20, 2024. The company has yet to release any details about what the flaws are other than listing their CVE identifiers -
- CVE-2024-46905 (CVSS score: 8.8)
- CVE-2024-46906 (CVSS score: 8.8)
- CVE-2024-46907 (CVSS score: 8.8)
- CVE-2024-46908 (CVSS score: 8.8)
- CVE-2024-46909 (CVSS score: 9.8), and
- CVE-2024-8785 (CVSS score: 9.8)
Security researcher Sina Kheirkhah of Summoning Team has been credited with discovering and reporting the first four flaws. Andy Niu of Trend Micro has been acknowledged for CVE-2024-46909, while Tenable has been credited for CVE-2024-8785.
It's worth noting that Trend Micro recently reported that threat actors are actively exploiting proof-of-concept (PoC) exploits for other recently disclosed security flaws in WhatsUp Gold to conduct opportunistic attacks.
Previously, the Shadowserver Foundation said it had observed exploitation attempts against CVE-2024-4885 (CVSS score: 9.8), another critical bug in WhatsUp Gold that was resolved by Progress in June 2024.
WhatsUp Gold Customers are recommended to apply the latest fixes as soon as possible to mitigate potential threats.
Update
A proof-of-concept (PoC) exploit code for CVE-2024-8785 has now been released by Tenable, making it crucial that system administrators apply the latest patches as soon as possible.
"A registry overwrite remote code execution vulnerability exists in NmAPI.exe in WhatsUp Gold versions prior to 24.0.1," the company said. "An unauthenticated remote attacker could leverage this vulnerability to achieve remote code execution on the affected system."
(The story was updated after publication on December 4, 2024, to include information related to the public availability of PoC for CVE-2024-8785.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/09/progress-software-releases-patches-for.html