Vulnerability record · CVE-2004-0798 · published 20 October 2004
CVE-2004-0798: Ipswitch WhatsUp Gold _maincfgret.cgi buffer overflow
Progress · Whatsup Gold
The _maincfgret.cgi script in Ipswitch WhatsUp Gold before 8.03 Hotfix 1 contains a buffer overflow reachable through a long instancename parameter. A remote attacker can trigger the overflow and execute arbitrary code on the affected server.
Description
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with public exploit code and very high EPSS, though the product is legacy and no KEV or ransomware use is recorded.
What it is
The _maincfgret.cgi script in Ipswitch WhatsUp Gold before 8.03 Hotfix 1 contains a buffer overflow reachable through a long instancename parameter. A remote attacker can trigger the overflow and execute arbitrary code on the affected server.
Impact
Successful exploitation gives the attacker remote code execution in the context of the web service, allowing full compromise of the WhatsUp Gold host and any data or credentials it holds.
Attack surface
The flaw is reached over the network via HTTP requests to _maincfgret.cgi; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
No CISA KEV listing and no ransomware association are recorded, but EPSS is 0.62577 (99th percentile) and a public Exploit-DB entry (566) exists, indicating exploit code is available and exploitation is plausible.
What to do
- Upgrade WhatsUp Gold to 8.03 Hotfix 1 or later, or apply the vendor patch referenced in the Ipswitch support page.
- If immediate patching is not possible, restrict network access to the WhatsUp Gold web interface to trusted management hosts only.
- Place the web interface behind a reverse proxy or WAF that filters oversized or malformed instancename parameters.
- Run the WhatsUp Gold service with least privilege and isolate the host from unrelated sensitive networks.
- Monitor vendor advisories for any further updates to this legacy product.
Detection
- Inspect web server and WhatsUp Gold logs for requests to _maincfgret.cgi with unusually long or malformed instancename parameters.
- Alert on crashes or restarts of the WhatsUp Gold CGI/web service that follow HTTP requests to _maincfgret.cgi.
- Search for known exploit payload patterns or shellcode indicators in HTTP request bodies targeting _maincfgret.cgi.
- Correlate outbound connections or child processes spawned by the WhatsUp Gold web service with unexpected activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0798 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0798), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.