CVE-2024-5011: WhatsUp Gold TestController Chart denial of service vulnerability
Published Jun 25, 2024
·Updated
In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTTP request to the TestController Chart functionality can lead to denial of service.
Affected Software
1 affected component
Progress WhatsUp Gold<23.1.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WhatsUp Goldto a version that resolves this vulnerability.Fixed in 2023.1.3
Event History
Jun 25, 2024
CVE Published
via MITRE·08:01 PM
Data Sourced
via MITRE·08:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5011?
CVE-2024-5011 has a medium severity level due to its potential to cause denial of service.
2
How do I fix CVE-2024-5011?
To fix CVE-2024-5011, upgrade WhatsUp Gold to version 23.1.3 or later.
3
What systems are affected by CVE-2024-5011?
CVE-2024-5011 affects WhatsUp Gold versions prior to 2023.1.3.
4
What kind of attack does CVE-2024-5011 facilitate?
CVE-2024-5011 allows for denial of service through an unauthenticated HTTP request.
5
Is authentication required to exploit CVE-2024-5011?
No, CVE-2024-5011 can be exploited without authentication.