Junglewise Threat Intelligence

CVE-2024-6670: Progress WhatsUp Gold SQL Injection Vulnerability

CVE-2024-6670 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-09-16

Technologies: Progress WhatsUp Gold. Vendors: Progress Software Corporation, Progress.

Executive brief

A SQL injection vulnerability in Progress WhatsUp Gold allows an unauthenticated remote attacker to retrieve encrypted user passwords. This issue is particularly impactful in configurations with a single user, potentially leading to full account compromise.

Affected products

  • Progress Software Corporation WhatsUp Gold versions released before 2024.0.0

Timeline

  • 2024-08-29: disclosed: Initial disclosure by Progress Software Corporation
  • 2024-09-16: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) catalog
  • 2024-09-16: exploited: Reported as exploited in the wild

Related threats