📦

whatsup_gold

Vendor: progress

Actively Exploited 2 CISA KEV List
PoC / Exploits 9 Code Available
Total RCEs 9 Remote Access
Total CVEs 63 Total Indexed
Avg. EPSS 18.51% Exploit Prob.
Latest CVE CVE-2025-2572 Apr 14

Security Vulnerability Index

Page 1 / 7
5.6 CVSS

In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.

EPSS: 0.01%
9.6 CVSS

In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.

EPSS: 21.75%
9.4 CVSS

In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.

EPSS: 32.66%
6.5 CVSS

In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.

EPSS: 9.37%
9.8 CVSS

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.

EPSS: 4.04%
9.8 CVSS

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.

EPSS: 40.81%
8.8 CVSS

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.

EPSS: 1.71%
8.8 CVSS

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.

EPSS: 1.71%
8.8 CVSS

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.

EPSS: 26.99%
8.8 CVSS

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin account.

EPSS: 1.71%