← Vulnerability feed

Vulnerability record · CVE-2004-0798 · published 20 October 2004

CVE-2004-0798: Ipswitch WhatsUp Gold _maincfgret.cgi buffer overflow

Progress · Whatsup Gold

The _maincfgret.cgi script in Ipswitch WhatsUp Gold before 8.03 Hotfix 1 contains a buffer overflow reachable through a long instancename parameter. A remote attacker can trigger the overflow and execute arbitrary code on the affected server.

7.5 CVSS 2.0 High EPSS 63% · top 0.8%
7.5CVSS 2.0 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution with public exploit code and very high EPSS, though the product is legacy and no KEV or ransomware use is recorded.

What it is

The _maincfgret.cgi script in Ipswitch WhatsUp Gold before 8.03 Hotfix 1 contains a buffer overflow reachable through a long instancename parameter. A remote attacker can trigger the overflow and execute arbitrary code on the affected server.

Impact

Successful exploitation gives the attacker remote code execution in the context of the web service, allowing full compromise of the WhatsUp Gold host and any data or credentials it holds.

Attack surface

The flaw is reached over the network via HTTP requests to _maincfgret.cgi; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

No CISA KEV listing and no ransomware association are recorded, but EPSS is 0.62577 (99th percentile) and a public Exploit-DB entry (566) exists, indicating exploit code is available and exploitation is plausible.

What to do

  • Upgrade WhatsUp Gold to 8.03 Hotfix 1 or later, or apply the vendor patch referenced in the Ipswitch support page.
  • If immediate patching is not possible, restrict network access to the WhatsUp Gold web interface to trusted management hosts only.
  • Place the web interface behind a reverse proxy or WAF that filters oversized or malformed instancename parameters.
  • Run the WhatsUp Gold service with least privilege and isolate the host from unrelated sensitive networks.
  • Monitor vendor advisories for any further updates to this legacy product.

Detection

  • Inspect web server and WhatsUp Gold logs for requests to _maincfgret.cgi with unusually long or malformed instancename parameters.
  • Alert on crashes or restarts of the WhatsUp Gold CGI/web service that follow HTTP requests to _maincfgret.cgi.
  • Search for known exploit payload patterns or shellcode indicators in HTTP request bodies targeting _maincfgret.cgi.
  • Correlate outbound connections or child processes spawned by the WhatsUp Gold web service with unexpected activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0798 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6670Progress WhatsUp Gold SQL Injection Exposes Encrypted PasswordsWhatsUp Gold versions before 2024.0.0 contain a SQL injection flaw (CWE-89) that an unauthenticated attacker can use to retrieve users' encrypted pas…KEVEPSS 93%analysed9.8CVE-2024-4885Progress WhatsUp Gold path traversal enables unauthenticated remote code executionWhatsUp Gold versions before 2023.1.3 contain a path traversal flaw in WhatsUp.ExportUtilities.Export.GetFileWithoutZip that allows unauthenticated a…KEVEPSS 99%analysed9.8CVE-2024-46909WhatsUp Gold pre-2024.0.1 remote code execution flawWhatsUp Gold versions before 2024.0.1 contain a flaw that lets a remote, unauthenticated attacker execute code in the context of the service account.…EPSS 49%analysed9.8CVE-2024-6671Progress whatsup gold sql injection vulnerabilityIn WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an …EPSS 19%9.8CVE-2024-4883WhatsUp Gold NmApi.exe unauthenticated remote code executionProgress WhatsUp Gold versions released before 2023.1.3 contain a remote code execution flaw reachable through NmApi.exe. An unauthenticated attacker…EPSS 65%analysed9.8CVE-2024-4884Progress whatsup gold command injection vulnerabilityIn WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.…EPSS 24%9.8CVE-2018-8938Progress whatsup gold code injection vulnerabilityA Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially cr…EPSS 2.3%9.8CVE-2018-8939Progress whatsup gold server-side request forgery (ssrf) vulnerabilityAn SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2004-0798), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.