ZeroHour
Security Affairspublished ()ingested @securityaffairs

Progress Software fixed 2 new critical flaws in WhatsUp Gold

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-46909
Unauthenticated RCE in Progress WhatsUp Gold (< 2024.0.1)

Progress WhatsUp Gold releases before 2024.0.1 contain a critical vulnerability that allows a remote, unauthenticated attacker to execute code in the context of the WhatsUp Gold service account; the associated weaknesses (CWE-16 configuration, CWE-22 path traversal, CWE-73 externally controlled file path) point to a file-path handling flaw. It is triggered over the network with no credentials, no special conditions, and no user interaction, which is why it scores 9.8 (critical) on CVSS 3.1. Successful exploitation gives an attacker code execution as the service account, which typically runs with high local privileges on the monitoring server and often holds credentials for the devices and networks being monitored. All deployments running any WhatsUp Gold version prior to 2024.0.1 are affected. No public proof-of-concept or CISA KEV listing is known, but the elevated EPSS score (48.9% probability of exploitation within 30 days, 99th percentile) suggests exploitation attempts are likely soon.

Do: Upgrade to WhatsUp Gold 2024.0.1 or later, which the vendor shipped alongside several other WhatsUp Gold fixes. If upgrading is delayed, restrict access to the WhatsUp Gold web interface to trusted management networks and review the privileges of the account under which the service runs. Because these servers frequently store credentials for monitored devices, treat them as high-value and check for indicators of compromise.

9.8
group max
49%
  • Progress WhatsUp Gold all versions released before 2024.0.1
largetens of thousands of on-prem deployments, of which likely only a few thousand are directly internet-exposed
CVE-2024-6670
Unauthenticated SQL Injection in Progress WhatsUp Gold (CVE-2024-6670)

CVE-2024-6670 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) in Progress Software's WhatsUp Gold network monitoring product, affecting all versions released before 2024.0.0. An unauthenticated attacker can trigger the flaw with crafted requests sent to the product over the network, requiring no privileges or user interaction. Successful exploitation lets the attacker retrieve WhatsUp Gold users' encrypted passwords, which can then potentially be cracked offline to gain valid credentials for further compromise. All organizations running affected releases — especially those with the WhatsUp Gold interface reachable beyond trusted internal networks — are exposed, and the flaw is one of two critical WhatsUp Gold issues Progress fixed in the 2024.0.0 release. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-16 with confirmed ransomware use, and EPSS assigns a ~93% probability of exploitation within 30 days, though no public proof-of-concept is catalogued for this flaw.

Do: Upgrade to WhatsUp Gold 2024.0.0 or later, the release that fixes this flaw; per CISA's KEV requirement, apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Because the flaw exposes encrypted user passwords, reset WhatsUp Gold credentials after patching and review logs for signs of exploitation, given known ransomware use.

9.893% KEV ransomware
  • Progress WhatsUp Gold All versions released before 2024.0.0
large≈10,000–100,000 on-prem deployments worldwide (internet-exposed subset likely in the thousands)
Full article314 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 29, 2024

Progress Software addresses six new security vulnerabilities affecting its WhatsUp Gold, two of them are rated as critical severity.

Progress Software has addressed six new security vulnerabilities in its IT infrastructure monitoring product WhatsUp Gold.

“The WhatsUp Gold team has identified six vulnerabilities that exist in versions below 24.0.1. We are reaching out to all WhatsUp Gold customers to upgrade their environment as soon as possible to version 24.0.1, released on Friday, September 20.” reads the advisory. “If you are running a version older than 24.0.1 and you do not upgrade, your environment will remain vulnerable. Please take the following steps as soon as possible: 

  1. Download the WhatsUp Gold 24.0.1 installer from https://community.progress.com/s/products-list
  2. Run the installer on your WhatsUp Gold server and follow the prompts. “

Two of the vulnerabilities fixed by Progress, respectively tracked as CVE-2024-8785 and CVE-2024-46909, are rated as critical severity.

CVE-2024-8785 (CVSS score of 9.8) was reported by Trend Micro researchers Andy Niu, while CVE-2024-46909 (CVSS score of 9.8) was reported by Tenable.

Below are the other vulnerabilities addressed by the company:

  • CVE-2024-46905 (CVSS score: 8.8)
  • CVE-2024-46906 (CVSS score: 8.8)
  • CVE-2024-46907 (CVSS score: 8.8)
  • CVE-2024-46908 (CVSS score: 8.8)

The company addressed the issues with version 24.0.1 released on September 20, 2024. The company has yet to disclose technical details about the vulnerabilities, it’s unclear if the are actively exploited in attacks in the wild.

In mid-September, U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress WhatsUp Gold SQL Injection vulnerability, tracked as CVE-2024-6670, to its Known Exploited Vulnerabilities catalog. An unauthenticated attacker could trigger this vulnerability to retrieve the users’ encrypted password. The flaw impacts WhatsUp Gold versions released before 2024.0.0.

    WhatsUp Gold Customers are recommended to address the above vulnerabilities as soon as possible.

    Follow me on Twitter: @securityaffairs and Facebook and Mastodon

    Pierluigi Paganini

    (SecurityAffairs – hacking, Progress Software)



    Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/169056/security/progress-software-whatsup-gold-critical-bugs.html