CVE-2024-46909: WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
Published Dec 2, 2024
·Updated
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
Affected Software
1 affected component
Progress WhatsUp Gold<24.0.1
Event History
Dec 2, 2024
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-46909?
CVE-2024-46909 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-46909?
To fix CVE-2024-46909, upgrade WhatsUp Gold to version 2024.0.1 or later.
3
Who is affected by CVE-2024-46909?
CVE-2024-46909 affects all versions of WhatsUp Gold prior to 2024.0.1.
4
Can CVE-2024-46909 be exploited remotely?
Yes, CVE-2024-46909 can be exploited by remote unauthenticated attackers.
5
What type of vulnerability is CVE-2024-46909?
CVE-2024-46909 is a code execution vulnerability that allows attackers to execute code in the context of the service account.