← Vulnerability feed

Vulnerability record · CVE-2005-1939 · published 31 December 2005

CVE-2005-1939: Ipswitch WhatsUp Small Business 2004 directory traversal in Report service

Ipswitch · Whatsup Small Business

Ipswitch WhatsUp Small Business 2004 contains a directory traversal flaw in its Report service on TCP port 8022. A remote attacker can supply ".." sequences in a request to read files outside the intended directory. Because the service is network-reachable and unauthenticated, it exposes file contents to anyone who can reach the port.

5.0 CVSS 2.0 Medium EPSS 64% · top 0.8%
5.0CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 10 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in a request to the Report service (TCP 8022).

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote file disclosure with public exploit references and very high EPSS probability, though impact is limited to confidentiality.

What it is

Ipswitch WhatsUp Small Business 2004 contains a directory traversal flaw in its Report service on TCP port 8022. A remote attacker can supply ".." sequences in a request to read files outside the intended directory. Because the service is network-reachable and unauthenticated, it exposes file contents to anyone who can reach the port.

Impact

An attacker gains read access to arbitrary files on the host, which can leak configuration data, credentials or other sensitive content. There is no write or code execution impact described in the record.

Attack surface

Reached over the network via the Report service on TCP 8022; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but multiple references are tagged Exploit and EPSS shows a 30-day probability of 0.63588 (99.177th percentile), indicating high likelihood of exploitation activity.

What to do

  • Apply the vendor patch or upgrade WhatsUp Small Business 2004 to a fixed release; the record does not specify fixed versions, so confirm with Ipswitch.
  • Restrict access to TCP 8022 to trusted management hosts using firewall or ACL rules.
  • Disable the Report service if it is not required.
  • Run the service with least privilege and isolate the host on a segmented management network.

Detection

  • Monitor network traffic to TCP 8022 for requests containing "../" or encoded traversal sequences.
  • Alert on Report service access from hosts outside the expected management subnet.
  • Review file access logs on the WhatsUp host for reads of files outside the report directory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-1939 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2005-1939), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.