CVE-2024-5012

In WhatsUp Gold versions released before 2023.1.3, there is amissing authentication vulnerability in WUGDataAccess.Credentials. Thisvulnerability allowsunauthenticated attackers to disclose Windows Credentials stored in the product Credential Library.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
ProgressSoftwareCNA
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CISA-ADPADP
---
---
CVEADP
---
---