CVE-2024-12108

Published Dec 31, 2024

Last updated 2 months ago

Overview

Description
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.
Source
security@progress.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.6
Impact score
5.8
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

security@progress.com
CWE-290
nvd@nist.gov
CWE-290

Social media

Hype score
Not currently trending
  1. CVE-2024-12108 (CVSS:9.6, CRITICAL) is Undergoing Analysis. In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public..https://t.co/EaPFICqjzz #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    5 Jan 2025

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. #Vulnerability #CVE202412105 CVE-2024-12108 (CVSS 9.6) and Beyond: Progress Issues Critical Patch for WhatsUp Gold Network Monitoring Software https://t.co/SuzjF60oSC

    @Komodosec

    2 Jan 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 Critical vulnerabilities alert: 🔹 WhatsUp Gold (CVE-2024-12108): PoC exploit released 🔹 Oracle WebLogic: Severe exploitation risks 🔍 Learn how to mitigate these threats: https://t.co/A0RCRZ6VZl #CyberSecurity #VulnerabilityManagement #PatchNow https://t.co/u5n9QbLUlk

    @socradar

    2 Jan 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2024-12108: Progress WhatsUp Gold Vulnerability #CVE-2024-12108 #WhatsUpGold #ProgreeSoftware https://t.co/I83PFGLxzG

    @pravin_karthik

    2 Jan 2025

    23 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 Upozorňujeme na dvě kritické zranitelnosti v nástroji Whatsup Gold. První zranitelnost, CVE-2024-12108, umožňuje útočníkovi získat úplnou kontrolu nad serverem WhatsUp Gold prostřednictvím veřejného API. Druhá zranitelnost, CVE-2024-12106, umožňuje neověřenému útočníkovi… http

    @GOVCERT_CZ

    2 Jan 2025

    412 Impressions

    1 Retweet

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 CVE Alert: Critical Progress WhatsUp Gold Authentication Bypass Vulnerability🚨 Vulnerability Details: CVE-2024-12108 (CVSS 9.6/10) Progress WhatsUp Gold Authentication Bypass Vulnerability Impact A successful exploit may allows an attacker to gain unauthorized access to the

    @CyberxtronTech

    2 Jan 2025

    52 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2024-12108 (CVSS 9.6) and Beyond: Progress Issues Critical Patch for WhatsUp Gold Network Monitoring Software https://t.co/4XnRen4Tpf

    @Dinosn

    2 Jan 2025

    1366 Impressions

    0 Retweets

    3 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨🚨Three Vulnerabilities in WhatsUp Gold CVE-2024-12108: Public API signing key rotation issue CVE-2024-12106: LDAP configuration interface leading to allowing attacker to configure LDAP settings without authentication CVE-2024-12105: SnmpExtendedActiveMonitor path traversal… ht

    @zoomeye_team

    2 Jan 2025

    631 Impressions

    2 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🗣 CVE-2024-12108 (CVSS 9.6) and Beyond: Progress Issues Critical Patch for WhatsUp Gold Network Monitoring Software https://t.co/34n2LDhzQY

    @fridaysecurity

    2 Jan 2025

    47 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. [CVE-2024-12108: CRITICAL] In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.#cybersecurity,#vulnerability https://t.co/GLNX867icu https://t.co/AKxf2TWcFj

    @CveFindCom

    31 Dec 2024

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations