First published: Thu Aug 29 2024(Updated: )
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
Credit: security@progress.com security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Software WhatsUp Gold | ||
Progress Software WhatsUp Gold | <24.0 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6670 has a high severity rating due to its potential for unauthorized access to sensitive user information.
To fix CVE-2024-6670, update Progress WhatsUp Gold to version 2024.0.0 or later.
CVE-2024-6670 is a SQL Injection vulnerability that allows unauthorized access to encrypted passwords.
CVE-2024-6670 affects all versions of Progress WhatsUp Gold released before 2024.0.0.
Yes, an attacker can exploit CVE-2024-6670 remotely without authentication.