CVE-2024-5013
- EPSS 1.39%
- Veröffentlicht 25.06.2024 21:16:00
- Zuletzt bearbeitet 21.11.2024 09:46:46
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. An unauthenticated attacker can put the application into the SetAdminPassword installation step, which renders the application non...
CVE-2024-5012
- EPSS 0.7%
- Veröffentlicht 25.06.2024 21:16:00
- Zuletzt bearbeitet 21.11.2024 09:46:46
In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Credentials. This vulnerability allows unauthenticated attackers to disclose Windows Credentials stored in the product Credential Libr...
CVE-2024-5011
- EPSS 7.22%
- Veröffentlicht 25.06.2024 20:15:13
- Zuletzt bearbeitet 21.11.2024 09:46:46
In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTTP request to the TestController Chart functionality can lead to denial of service.
CVE-2024-5010
- EPSS 22.55%
- Veröffentlicht 25.06.2024 20:15:13
- Zuletzt bearbeitet 21.11.2024 09:46:46
In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality. A specially crafted unauthenticated HTTP request can lead to a disclosure of sensitive information.
CVE-2024-5009
- EPSS 36.39%
- Veröffentlicht 25.06.2024 20:15:13
- Zuletzt bearbeitet 21.11.2024 09:46:46
In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword allows local attackers to modify admin's password.
CVE-2024-5008
- EPSS 27.19%
- Veröffentlicht 25.06.2024 20:15:13
- Zuletzt bearbeitet 21.11.2024 09:46:46
In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using Apm.UI.Areas.APM.Controllers.Api.Applications.AppProfileImportController.
CVE-2024-4884
- EPSS 58.44%
- Veröffentlicht 25.06.2024 20:15:12
- Zuletzt bearbeitet 21.11.2024 09:43:47
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileg...
CVE-2024-4885
- EPSS 94.2%
- Veröffentlicht 25.06.2024 20:15:12
- Zuletzt bearbeitet 10.03.2025 20:24:16
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole priv...
CVE-2024-4883
- EPSS 85.64%
- Veröffentlicht 25.06.2024 20:15:12
- Zuletzt bearbeitet 21.11.2024 09:43:47
In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.
CVE-2024-4562
- EPSS 0.15%
- Veröffentlicht 14.05.2024 21:15:13
- Zuletzt bearbeitet 09.12.2024 13:40:22
In WhatsUp Gold versions released before 2023.1.2 , an SSRF vulnerability exists in Whatsup Gold's Issue exists in the HTTP Monitoring functionality. Due to the lack of proper authorization, any authenticated user can access the HTTP monitori...