Tuesday, January 14, 2025

Progress urges admins to patch crucial WhatsUp Gold bugs ASAP


Progress Software program warned prospects to patch a number of crucial and high-severity vulnerabilities in its WhatsUp Gold community monitoring software as quickly as doable.

Nonetheless, though it launched WhatsUp Gold 24.0.1, which addressed the problems final Friday and printed an advisory on Tuesday, the corporate has but to supply any particulars concerning these flaws.

“The WhatsUp Gold crew has recognized six vulnerabilities that exist in variations under 24.0.1,” Progress warned prospects this week.

“We’re reaching out to all WhatsUp Gold prospects to improve their setting as quickly as doable to model 24.0.1, launched on Friday, September 20. In case you are working a model older than 24.0.1 and you don’t improve, your setting will stay susceptible.”

The one data accessible is that the six vulnerabilities had been reported by Summoning Group’s Sina Kheirkhah, Pattern Micro’s Andy Niu, and Tenable researchers and had been assigned the next CVE IDs and CVSS base scores:

To improve to the newest model, obtain the WhatsUp Gold 24.0.1 installer from right here, run it on susceptible WhatsUp Gold servers, and observe the prompts.

BleepingComputer contacted Progress to request extra particulars about these flaws, however a response was not instantly accessible.

Since August 30, attackers have been exploiting two WhatsUp Gold SQL injection vulnerabilities tracked as CVE-2024-6670 and CVE-2024-6671. Each flaws had been patched on August 16 after being reported to Progress by safety researcher Sina Kheirkhah by way of the Zero Day Initiative (ZDI) on Might 22.

Kheirkhah launched proof-of-concept (PoC) exploit code for the vulnerabilities two weeks after they had been fastened on August 30 (cybersecurity agency Pattern Micro believes the attackers have used his PoC exploit to bypass authentication and obtain distant code execution).

In early August, menace monitoring group Shadowserver Basis additionally noticed makes an attempt to use CVE-2024-4885, a crucial distant code execution WhatsUp Gold vulnerability disclosed on June 25. Kheirkhah additionally found CVE-2024-4885 and printed full particulars on his weblog two weeks later.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles

PHP Code Snippets Powered By : XYZScripts.com