CVE-2024-5013: WhatsUp Gold InstallController Denial-of-Service Vulnerability
Published Jun 25, 2024
·Updated
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service
vulnerability was identified. An unauthenticated attacker can put the application into the SetAdminPassword installation step, which renders the application non-accessible.
Affected Software
1 affected component
Progress WhatsUp Gold<23.1.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WhatsUp Goldto a version that resolves this vulnerability.Fixed in 2023.1.3
Event History
Jun 25, 2024
CVE Published
via MITRE·08:11 PM
Data Sourced
via MITRE·08:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5013?
CVE-2024-5013 is classified as a Denial of Service vulnerability.
2
How do I fix CVE-2024-5013?
To resolve CVE-2024-5013, upgrade WhatsUp Gold to version 2023.1.3 or later.
3
Who is affected by CVE-2024-5013?
CVE-2024-5013 affects WhatsUp Gold versions prior to 2023.1.3.
4
Can CVE-2024-5013 be exploited remotely?
Yes, CVE-2024-5013 can be exploited by an unauthenticated remote attacker.
5
What impact does CVE-2024-5013 have on the application?
CVE-2024-5013 can render the WhatsUp Gold application non-accessible.