VDB

CVE-2024-4885

CVE-2024-4885 PUBLISHED KEV CVSS 9.800000190734863 CRITICAL

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.

EPSS 94.27% · 99.9th percentile

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
94.27%
99.9th percentile

Affected Products

VendorProductVersions
progresswhatsup_gold2023.1.0
Progress Software CorporationWhatsUp Gold2023.1.0
progresswhatsup_gold0

Timeline

  • Jun 25, 2024 CVE Published
  • Jun 26, 2024 EPSS Score
  • Jul 18, 2024 EPSS Score
  • Sep 1, 2024 EPSS Score
  • Sep 7, 2024 EPSS Score
  • Sep 18, 2024 PoC Published
  • Sep 24, 2024 EPSS Score
  • Oct 5, 2024 Coalition ESS Score
  • Oct 16, 2024 EPSS Score
  • Nov 8, 2024 EPSS Score
  • Nov 30, 2024 EPSS Score
  • Dec 7, 2024 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›