PT-2024-17444 · Ipswitch · Whatsup Gold

Published

2024-12-31

·

Updated

2025-01-07

·

CVE-2024-12108

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WhatsUp Gold versions prior to 2024.0.2
Description An attacker can gain access to the WhatsUp Gold server via the public API. This issue allows unauthorized access, potentially leading to further exploitation. The estimated number of affected devices and real-world incidents are not specified.
Recommendations For versions prior to 2024.0.2, update to version 2024.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the public API until a patch is applied. Avoid using the public API for sensitive operations until the issue is resolved.

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2024-12108

Affected Products

Whatsup Gold