CVE-2024-5013

HIGH

WhatsUp Gold < 23.1.3 - Unauthenticated Denial of Service via SetAdminPassword Installation Step

Title source: llm
STIX 2.1

Description

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. An unauthenticated attacker can put the application into the SetAdminPassword installation step, which renders the application non-accessible.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0139
EPSS Percentile 80.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (1)
progress/whatsup_gold < 23.1.3
Published Jun 25, 2024
Tracked Since Feb 18, 2026