In WhatsUp Gold versions released before 2024.0.0,  an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.
History

Wed, 30 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:*

Mon, 28 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress whatsup Gold
CPEs cpe:2.3:a:progress_software:whatsup_gold:*:*:*:*:*:*:*:* cpe:2.3:a:progress:whatsup_gold:-:*:*:*:*:*:*:*
Vendors & Products Progress Software
Progress Software whatsup Gold
Progress
Progress whatsup Gold

Fri, 25 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Progress Software
Progress Software whatsup Gold
CPEs cpe:2.3:a:progress_software:whatsup_gold:*:*:*:*:*:*:*:*
Vendors & Products Progress Software
Progress Software whatsup Gold
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Oct 2024 20:30:00 +0000

Type Values Removed Values Added
Description In WhatsUp Gold versions released before 2024.0.0,  an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.
Title WhatsUp Gold getReport Missing Authentication Authentication Bypass Vulnerability
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published: 2024-10-24T20:11:50.614Z

Updated: 2024-10-29T03:55:09.900Z

Reserved: 2024-08-13T18:22:43.153Z

Link: CVE-2024-7763

cve-icon Vulnrichment

Updated: 2024-10-25T15:38:20.031Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-24T21:15:15.033

Modified: 2024-10-30T14:13:45.763

Link: CVE-2024-7763

cve-icon Redhat

No data.