Critical Progress WhatsUp RCE flaw now under active exploitation
ID: c1e61eaa-8448-5105-906b-2d19f7d81a33
STIX ID: report--c1e61eaa-8448-5105-906b-2d19f7d81a33
Feed Name: Bleeping Computer
Progress WhatsUp Gold versions 23.1.2 and older are vulnerable to CVE-2024-4885, a critical unauthenticated remote code execution flaw (CVSS 9.8). Public proof-of-concept exploits target the /NmAPI/RecurringReport endpoint and Shadowserver reported exploitation attempts from six IPs beginning August 1, 2024; administrators are advised to upgrade to 23.1.3, restrict endpoint access to trusted IPs/behind VPNs or firewalls, and monitor for suspicious activity and potential webshells.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
