CVE-2024-4884

In WhatsUp Gold versions released before 2023.1.3,an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.The Apm.UI.Areas.APM.Controllers.CommunityController

 allows execution of commands with iisapppool\nmconsole privileges.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProgressSoftwareCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
CVEADP
---
---