In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate information related to a registered device being monitored by WhatsUp Gold.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-862 |
Wed, 16 Oct 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate information related to a registered device being monitored by WhatsUp Gold. | In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate information related to a registered device being monitored by WhatsUp Gold. |
MITRE
Status: PUBLISHED
Assigner: ProgressSoftware
Published: 2023-12-14T16:06:29.101Z
Updated: 2024-10-16T14:36:49.428Z
Reserved: 2023-11-28T16:03:22.473Z
Link: CVE-2023-6368
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-14T16:15:54.103
Modified: 2024-11-21T08:43:43.327
Link: CVE-2023-6368
Redhat
No data.