In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.
References
Link | Resource |
---|---|
https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-December-2023 | Vendor Advisory |
https://www.progress.com/network-monitoring | Product |
Configurations
History
No history.
Information
Published : 2023-12-14 16:15
Updated : 2023-12-19 17:51
NVD link : CVE-2023-6595
Mitre link : CVE-2023-6595
CVE.ORG link : CVE-2023-6595
JSON object : View
Products Affected
progress
- whatsup_gold