VDB

CVE-2024-4884

CVE-2024-4884 PUBLISHED CVSS 9.800000190734863 CRITICAL

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileges.

EPSS 24.31% · 97.8th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
24.31%
97.8th percentile

Affected Products

VendorProductVersions
progresswhatsup_gold0, 0
progresswhatsup_gold2023.1.0, 2023.1.0
Progress Software CorporationWhatsUp Gold2023.1.0, 2023.1.0

Timeline

  • Jun 25, 2024 CVE Published
  • Jun 26, 2024 EPSS Score
  • Jul 19, 2024 EPSS Score
  • Sep 2, 2024 EPSS Score
  • Sep 24, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Nov 8, 2024 EPSS Score
  • Dec 2, 2024 EPSS Score
  • Dec 24, 2024 EPSS Score
  • Feb 8, 2025 EPSS Score
  • Mar 2, 2025 EPSS Score
  • Mar 4, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›