Progress WhatsUp Gold Security Update – 01 September 2024

Progress has released a security update to address several vulnerabilities affecting WhatsUp Gold versions before 2024.0.0.

The addressed vulnerabilities could allow the remote attacker to perform SQL injection attacks on the affected system by sending specially crafted SQL statements.

Sample of the addressed vulnerabilities:

1. Progress Software WhatsUp Gold SQL Injection (CVE-2024-6670):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Data Manipulation

2. Progress Software WhatsUp Gold SQL Injection (CVE-2024-6672):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Data Manipulation
Vulnerabilities
  • CVE-2024-6670
  • CVE-2024-6671
  • CVE-2024-6672
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Progress WhatsUp Gold Security Update

References