PT-2024-9444 · Progress · Whatsup Gold

Published

2024-08-16

·

Updated

2026-02-09

·

CVE-2024-6671

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Progress Software WhatsUp Gold versions prior to 2024.0.0
Description The WhatsUp Gold network monitoring system is affected by a SQL injection issue due to a lack of protection for the SQL query structure. This allows a remote attacker to bypass authentication and retrieve the encrypted password of a single user if the application is configured with only one user. No information is available regarding the number of potentially affected devices or real-world incidents. The issue resides in the GetStatisticalMonitorList function. The vulnerability allows an unauthenticated attacker to access the encrypted password of a user.
Recommendations Update WhatsUp Gold to version 2024.0.0 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-11139
CVE-2024-6671
ZDI-24-1186

Affected Products

Whatsup Gold