Progress urges admins to patch critical WhatsUp Gold bugs ASAP

Teilen:

Progress Software warned customers to patch multiple critical and high-severity vulnerabilities in its WhatsUp Gold network monitoring tool as soon as possible.

However, even though it released WhatsUp Gold 24.0.1, which addressed the issues last Friday and published an Beratung on Tuesday, the company has yet to provide any details regarding these flaws.

“The WhatsUp Gold team has identified six vulnerabilities that exist in versions below 24.0.1,” Progress warned customers this week.

“We are reaching out to all WhatsUp Gold customers to upgrade their environment as soon as possible to version 24.0.1, released on Friday, September 20. If you are running a version older than 24.0.1 and you do not upgrade, your environment will remain vulnerable.”

The only information available is that the six vulnerabilities were reported by Summoning Team’s Sina Kheirkhah, Trend Micro’s Andy Niu, and Tenable researchers and were assigned the following CVE IDs and CVSS base scores:

To upgrade to the latest version, download the WhatsUp Gold 24.0.1 installer from here, run it on vulnerable WhatsUp Gold servers, and follow the prompts.

BleepingComputer contacted Progress to request more details about these flaws, but a response was not immediately available.

Since August 30, attackers have been exploiting two WhatsUp Gold SQL injection vulnerabilities tracked as CVE-2024-6670 and CVE-2024-6671. Both flaws were patched on August 16 after being reported to Progress by security researcher Sina Kheirkhah through the Zero Day Initiative (ZDI) on May 22.

Kheirkhah released proof-of-concept (PoC) exploit code for the vulnerabilities two weeks after they were fixed on August 30 (cybersecurity firm Trend Micro believes the attackers have used his PoC exploit to bypass authentication and achieve remote code execution).

In early August, threat monitoring organization Shadowserver Foundation also observed attempts to exploit CVE-2024-4885, a critical remote code execution WhatsUp Gold vulnerability disclosed on June 25. Kheirkhah also discovered CVE-2024-4885 and published full details on his blog two weeks later.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:51 am, Jan. 27, 2025
Wetter-Symbol 8°C
L: 7° | H: 8°
broken clouds
Luftfeuchtigkeit: 86 %
Druck: 981 mb
Wind: 14 mph SW
Windböe: 26 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 61%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:45 am
Sonnenuntergang: 4:40 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
7° | 8°°C 1 mm 100% 19 mph 86 % 985 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
6° | 8°°C 1 mm 100% 20 mph 89 % 996 mb 0 mm/h
Mi. Jan. 29 9:00 pm
Wetter-Symbol
5° | 7°°C 1 mm 100% 13 mph 94 % 1005 mb 0 mm/h
Do. Jan. 30 9:00 pm
Wetter-Symbol
3° | 6°°C 1 mm 100% 13 mph 95 % 1026 mb 0 mm/h
Fr. Jan. 31 9:00 pm
Wetter-Symbol
2° | 5°°C 1 mm 100% 8 mph 93 % 1031 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
7° | 8°°C 0.8 mm 80% 14 mph 86 % 982 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
7° | 7°°C 0 mm 0% 18 mph 79 % 983 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
5° | 6°°C 0.76 mm 76% 19 mph 83 % 985 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
7° | 7°°C 1 mm 100% 15 mph 76 % 984 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
7° | 7°°C 1 mm 100% 16 mph 81 % 984 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
7° | 7°°C 1 mm 100% 17 mph 76 % 983 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
6° | 6°°C 1 mm 100% 20 mph 89 % 980 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
8° | 8°°C 1 mm 100% 19 mph 87 % 979 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€95,803.54
-4.53%
Ethereum(ETH)
€3,014.90
-5.75%
XRP(XRP)
€2.83
-5.31%
Fesseln(USDT)
€0.95
-0.03%
Solana(SOL)
€221.45
-10.40%
USDC(USDC)
€0.95
0.00%
Dogecoin(DOGE)
€0.310887
-8.48%
Shiba Inu(SHIB)
€0.000017
-8.21%
Pepe(PEPE)
€0.000012
-13.82%
Peanut das Eichhörnchen(PNUT)
€0.342367
3.03%
Nach oben scrollen