VDB
CVE-2024-4884
CVE-2024-4884
PUBLISHED
CVSS 9.800000190734863 CRITICAL
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileges.
EPSS 55.49% · 98.1th percentile
Risk Scores
CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
55.49%
98.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| progress | whatsup_gold | 0 |
| progress | whatsup_gold | 2023.1.0 |
| Progress Software Corporation | WhatsUp Gold | 2023.1.0 |
Timeline
- Jun 25, 2024 CVE Published
- Jun 26, 2024 EPSS Score
- Jul 18, 2024 EPSS Score
- Aug 1, 2024 CVE Updated
- Sep 1, 2024 EPSS Score
- Sep 24, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 16, 2024 EPSS Score
- Nov 30, 2024 EPSS Score
- Dec 24, 2024 EPSS Score
- Jan 15, 2025 EPSS Score
- Feb 6, 2025 EPSS Score