WhatsUp Gold Unauthenticated Access to an API Endpoint
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.8%
exploitation probability
0.8%top 45% of all CVEs
observed exploitation
nono source reports it
In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Progress Software Corporation · WhatsUp Gold