CRITICAL

CVE-2024-4885

Progress Whatsup Gold 2024-06-25 CVSS v3.1
CVSS
9.8
KEV

Description

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The

WhatsUp.ExportUtilities.Export.GetFileWithoutZip



allows execution of commands with iisapppool\nmconsole privileges.

Summary dbcve.org

An unauthenticated Remote Code Execution vulnerability exists in Progress WhatsUp Gold's ExportUtilities.Export.GetFileWithoutZip function in versions prior to 2023.1.3. Attackers can execute arbitrary commands with iisapppool\nmconsole (IIS application pool) privileges without any authentication, achieving remote code execution on the affected system.

Mitigation

Upgrade WhatsUp Gold to version 2023.1.3 or later to patch the vulnerability. Given the unauthenticated nature and critical CVSS score, prioritize this upgrade immediately and restrict network exposure to the application until patched.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

99.29%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE