ZDI-CAN-24003: ZDI-24-893: Progress Software WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability
Published Jul 3, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software WhatsUp Gold. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-4885.
Affected Software
1 affected component
Progress Software WhatsUp Gold
Event History
Jul 3, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-24003?
The severity of ZDI-CAN-24003 is rated at 9.8 on the CVSS scale, indicating critical impact.
2
How do I fix ZDI-CAN-24003?
To fix ZDI-CAN-24003, update Progress Software WhatsUp Gold to the latest version provided by the vendor.
3
What type of attack does ZDI-CAN-24003 allow?
ZDI-CAN-24003 allows remote attackers to execute arbitrary code on affected systems.
4
Is authentication required to exploit ZDI-CAN-24003?
No, authentication is not required to exploit ZDI-CAN-24003, making it easier for attackers.
5
Which software is affected by ZDI-CAN-24003?
ZDI-CAN-24003 affects installations of Progress Software WhatsUp Gold.