- Description
- In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.
- Source
- security@progress.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Progress WhatsUp Gold Path Traversal Vulnerability
- Exploit added on
- Mar 3, 2025
- Exploit action due
- Mar 24, 2025
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- security@progress.com
- CWE-22
- nvd@nist.gov
- NVD-CWE-noinfo
- Hype score
- Not currently trending
CISAは、既知の悪用されている脆弱性カタログに新たに5つの脆弱性を追加したことを発表しました。 ・CVE-2023-20118 ・CVE-2022-43939 ・CVE-2022-43769 ・CVE-2018-8639 ・CVE-2024-4885 https://t.co/Exu8c4xTLv https://t.co/qxdw1Rse1y
@t_nihonmatsu
5 Mar 2025
231 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
今日の #EPSS #脆弱性 情報はこんな感じ WhatsUp Goldの脆弱性CVE-2024-4885がいっきに値を挙げています。子の脆弱性は攻撃を観測、KEVに3月3日に登録済です。 https://t.co/Px2dKhQ6MO
@papa_anniekey
5 Mar 2025
459 Impressions
2 Retweets
4 Likes
0 Bookmarks
1 Reply
0 Quotes
Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2024-4885 #Progress WhatsUp Gold Path Traversal Vulnerability https://t.co/y2ORGKEUAR
@ScyScan
4 Mar 2025
25 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
⚠️ Vulnerability Alert: Progress WhatsUp Gold Path Traversal Vulnerability 📅 Timeline: Disclosure: 2024-06-25, Patch: 2025-03-03 📌 Attribution: 🆔cveId: CVE-2024-4885 📊baseScore: 9.8 📏cvssMetrics: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvssSeverity: Critical 🔴… https://t.co
@syedaquib77
4 Mar 2025
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C22487E3-6723-40C7-86A0-764EBAA37A55",
"versionEndExcluding": "23.1.3"
}
],
"operator": "OR"
}
]
}
]