PT-2024-9442 · Ipswitch · Whatsup Gold

Published

2024-08-16

·

Updated

2025-10-31

·

CVE-2024-6670

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: WhatsUp Gold versions prior to 2024.0.0
Description: The issue is related to a SQL Injection vulnerability in WhatsUp Gold, which can be exploited by an unauthenticated attacker to retrieve a user's encrypted password. The vulnerability is actively exploited in the wild and has been integrated into various exploit tools. It is estimated that over 3,400 services are potentially affected. The vulnerability can be exploited without prior authentication or special privileges, making it particularly dangerous.
Recommendations: For versions prior to 2024.0.0, update to version 2024.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the /NmConsole/Platform/PerformanceMonitorErrors/HasErrors endpoint until a patch is available. Additionally, avoid using vulnerable parameters in affected API endpoints until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-11137
BDU:2024-11139
CVE-2024-6670
ZDI-24-1185

Affected Products

Whatsup Gold