CVE-2024-4884

CRITICAL

WhatsUp Gold < 23.1.3 - Unauthenticated Remote Code Execution via CommunityController

Title source: llm
STIX 2.1

Description

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileges.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.5549
EPSS Percentile 98.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78 CWE-94 CWE-77
Status published
Products (1)
progress/whatsup_gold < 23.1.3
Published Jun 25, 2024
Tracked Since Feb 18, 2026