CVE-2024-12106

Published Dec 31, 2024

Last updated 2 months ago

Overview

Description
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.
Source
security@progress.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity
HIGH

Weaknesses

security@progress.com
CWE-306
nvd@nist.gov
CWE-306

Social media

Hype score
Not currently trending
  1. CVE-2024-12106 WhatsUpGold Pre-Auth LDAP Config and Password Theft https://t.co/rjpaHCEHzC

    @int20z

    24 Jan 2025

    1094 Impressions

    8 Retweets

    25 Likes

    4 Bookmarks

    1 Reply

    0 Quotes

  2. CVE-2024-12106 (CVSS:9.4, CRITICAL) is Undergoing Analysis. In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings...https://t.co/gAv35JXBOW #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    5 Jan 2025

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 Upozorňujeme na dvě kritické zranitelnosti v nástroji Whatsup Gold. První zranitelnost, CVE-2024-12108, umožňuje útočníkovi získat úplnou kontrolu nad serverem WhatsUp Gold prostřednictvím veřejného API. Druhá zranitelnost, CVE-2024-12106, umožňuje neověřenému útočníkovi… http

    @GOVCERT_CZ

    2 Jan 2025

    412 Impressions

    1 Retweet

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨🚨Three Vulnerabilities in WhatsUp Gold CVE-2024-12108: Public API signing key rotation issue CVE-2024-12106: LDAP configuration interface leading to allowing attacker to configure LDAP settings without authentication CVE-2024-12105: SnmpExtendedActiveMonitor path traversal… ht

    @zoomeye_team

    2 Jan 2025

    631 Impressions

    2 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. [CVE-2024-12106: CRITICAL] In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.#cybersecurity,#vulnerability https://t.co/pM8pYzKLb7 https://t.co/dDZ18AP33I

    @CveFindCom

    31 Dec 2024

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-12106 In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings. https://t.co/urZOtt09Kl

    @CVEnew

    31 Dec 2024

    285 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations