PT-2025-16257 · Ipswitch · Whatsup Gold

Jimi

·

Published

2025-04-14

·

Updated

2025-07-17

·

CVE-2025-2572

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WhatsUp Gold versions prior to 2024.0.3
Description A database manipulation issue allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup. This enables attackers to tamper with the database without authentication.
Recommendations For versions prior to 2024.0.3, update to version 2024.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the NmConfigurationManager.exe to minimize the risk of exploitation. Avoid using the WhatsUp.dbo.WrlsMacAddressGroup until the issue is resolved.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-2572

Affected Products

Whatsup Gold