Whatsup Gold, Observium and Offis vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-12105 | Authenticated path traversal in Progress WhatsUp Gold versions before 2024.0.2 Progress WhatsUp Gold versions released before 2024.0.2 contain an information-disclosure flaw classified as CWE-22 (path traversal), in which an authenticated user can send a specially crafted HTTP request to access resources outside the intended directory. The issue is reachable over the network with low privileges and no user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N). A successful exploit yields a high confidentiality impact — the attacker can read sensitive data or files accessible to the application — with no integrity or availability impact. Any organization running an affected WhatsUp Gold release is exposed, especially where the web interface is reachable by accounts an attacker could obtain or compromise. No public proof of concept or CISA KEV listing exists yet, but the EPSS score of 42.4% (99th percentile) suggests a substantial probability of exploitation within 30 days. Do: Upgrade to WhatsUp Gold 2024.0.2 or later. In the interim, inventory and restrict WhatsUp Gold web interfaces to trusted networks, and review or rotate low-privileged accounts that could be used to send the crafted request. Given the elevated EPSS (42.4%, 99th percentile), prioritize patching even though no public PoC or confirmed in-the-wild exploitation is currently known. | 6.5 | 42% |
| largetens of thousands of WhatsUp Gold deployments worldwide, with on the order of a few thousand instances internet-exposed per public scans (estimate; exact… | ||
| CVE-2024-28130 | An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — | |
| CVE-2024-47002 | A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted HTTP request can lead to an arbitrary html code. An authenticated user would need to click a malicious link provided by the attacker. NVD description · AI analysis pending | 5.4 | 15% | PoC ×2 |
| — | |
| CVE-2024-47796 +1 in the same advisory: …52333 | An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. NVD description · AI analysis pending | 7.8 | <1% | PoC ×2 |
| — | |
| CVE-2024-5010 | In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality. In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality. A specially crafted unauthenticated HTTP request can lead to a disclosure of sensitive information. NVD description · AI analysis pending | 7.5 group max | 70% |
| — |
Full article307 words · extracted from blog.talosintelligence.com · click to collapse
Wednesday, January 29, 2025 11:45
Cisco Talos’ Vulnerability Research team recently disclosed three vulnerabilities in Observium, three vulnerabilities in Offis, and four vulnerabilities in Whatsup Gold.
These vulnerabilities exist in Observium, a network observation and monitoring system; Offis DCMTK, a collection of libraries and applications implementing DICOM (Digital Imaging and Communications in Medicine) standard formats; and WhatsUp Gold, an IT infrastructure management product.
The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy.
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website.
Observium Vulnerabilities
Discovered by Marcin "Icewall" Noga.
Two cross-site scripting vulnerabilities exist in Observium, which can lead to arbitrary JavaScript code execution, as well as one HTML code injection vulnerability. All three can be triggered by an authenticated user clicking a malicious link crafted by the attacker.
- TALOS-2024-2090 (CVE-2024-47140)
- TALOS-2024-2091 (CVE-2024-47002)
- TALOS-2024-2092 (CVE-2024-45061)
Offis Vulnerabilities
Discovered by Emmanuel Tacheau.
Three vulnerabilities were found in the Offis DCMTK libraries that support the DICOM standard format. TALOS-2024-1957 (CVE-2024-28130) is an incorrect type conversion vulnerability that can lead to arbitrary code execution, and TALOS-2024-2121 (CVE-2024-52333) and TALOS-2024-2122 (CVE-2024-47796) are improper array index validation vulnerabilities that can lead to out-of-bounds write capabilities. All can be triggered with specially crafted malicious DICOM files.
Whatsup Gold Vulnerabilities
Discovered by Marcin "Icewall" Noga.
Two Whatsup Gold vulnerabilities include a risk of information disclosure (TALOS-2024-1932 (CVE-2024-5017) and TALOS-2024-2089 (CVE-2024-12105)), which can be triggered by an attacker making an authenticated HTTP request.
There is also a risk of disclosure of sensitive information (TALOS-2024-1933 (CVE-2024-5010)), and denial of service (TALOS-2024-1934 (CVE-2024-5011)). These two vulnerabilities can be triggered by an attacker making an unauthenticated HTTP request.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/whatsup-gold-observium-offis-vulnerabilities/