WhatsUp Gold vulnerability puts sensitive information at risk
CVE-2024-5010
7.5HIGH
Summary
A significant vulnerability has been identified in WhatsUp Gold, specifically in the TestController functionality of versions released before 2023.1.3. This vulnerability allows for a specially crafted HTTP request to be sent without authentication, which can lead to the disclosure of sensitive information. This poses a notable risk to users who rely on this network monitoring tool, as unauthorized parties may gain access to critical data. It is recommended that users upgrade to the latest version to mitigate any potential threats associated with this vulnerability.
Affected Version(s)
WhatsUp Gold Windows 2023.1.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Discovered by Marcin 'Icewall' Noga of Cisco Talos.