CVE-2024-46909

In WhatsUp Gold versions released before 2024.0.1, aremote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProgressSoftwareCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
progresswhatsup_gold
𝑥
< 24.0.1
𝑥
= Vulnerable software versions
Common Weakness Enumeration