PT-2022-19873 · Ipswitch · Ipswitch Whatsup Gold

Published

2022-05-11

·

Updated

2024-08-27

·

CVE-2022-29847

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ipswitch WhatsUp Gold versions 21.0.0 through 21.1.1 Ipswitch WhatsUp Gold version 22.0.0
Description The issue allows an unauthenticated attacker to invoke an API transaction, enabling them to relay encrypted user credentials to an arbitrary host.
Recommendations For Ipswitch WhatsUp Gold versions 21.0.0 through 21.1.1, update to a version that fixes this issue. For Ipswitch WhatsUp Gold version 22.0.0, update to a version that fixes this issue. As a temporary workaround, consider restricting access to the API endpoint to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-29847

Affected Products

Ipswitch Whatsup Gold