ZDI-CAN-23659: ZDI-24-888: Progress Software WhatsUp Gold Missing Authentication GetWindowsCredential Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Progress Software WhatsUp Gold. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-5015.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23659?
The severity of ZDI-CAN-23659 is rated at 7.5 on the CVSS scale.
What type of information can be disclosed due to ZDI-CAN-23659?
ZDI-CAN-23659 allows remote attackers to disclose sensitive information from affected installations of Progress Software WhatsUp Gold.
Is authentication required to exploit ZDI-CAN-23659?
No, authentication is not required to exploit ZDI-CAN-23659.
What versions of Progress Software WhatsUp Gold are affected by ZDI-CAN-23659?
ZDI-CAN-23659 affects certain installations of Progress Software WhatsUp Gold without specifying particular versions.
How can organizations protect against ZDI-CAN-23659?
Organizations should apply patches provided by Progress Software and implement network security measures to restrict unauthorized access.