I
n WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.
References
| Link | Resource |
|---|---|
| https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-December-2023 | Vendor Advisory |
| https://www.progress.com/network-monitoring | Product |
| https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-December-2023 | Vendor Advisory |
| https://www.progress.com/network-monitoring | Product |
Configurations
History
21 Nov 2024, 08:44
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-December-2023 - Vendor Advisory | |
| References | () https://www.progress.com/network-monitoring - Product | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
16 Oct 2024, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | ||
| Summary | (en) In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold. |
Information
Published : 2023-12-14 16:15
Updated : 2024-11-21 08:44
NVD link : CVE-2023-6595
Mitre link : CVE-2023-6595
CVE.ORG link : CVE-2023-6595
JSON object : View
Products Affected
CWE
CWE-306
Missing Authentication for Critical Function