CVE-2024-5008: WhatsUp Gold APM Unrestricted File Upload Remote Code Execution Vulnerability
In WhatsUp Gold versions released before 2023.1.3,
an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using Apm.UI.Areas.APM.Controllers.Api.Applications.AppProfileImportController.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WhatsUp Goldto a version that resolves this vulnerability.Fixed in 2023.1.3
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5008?
CVE-2024-5008 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2024-5008?
To fix CVE-2024-5008, upgrade WhatsUp Gold to version 23.1.3 or later.
Who is affected by CVE-2024-5008?
CVE-2024-5008 affects authenticated users in WhatsUp Gold versions earlier than 23.1.3.
What type of vulnerability is CVE-2024-5008?
CVE-2024-5008 is a file upload vulnerability that can lead to remote code execution.
Is there a workaround for CVE-2024-5008?
There are no known workarounds for CVE-2024-5008 other than applying the security update.