← Vulnerability feed

Vulnerability record · CVE-2011-4722 · published 28 December 2014

CVE-2011-4722: Ipswitch WhatsUp Gold TFTP Server directory traversal file read

Ipswitch · Tftp Server

The TFTP Server component (version 1.0.0.24) in Ipswitch WhatsUp Gold is vulnerable to directory traversal. A remote attacker can place a .. sequence in the Filename field of a TFTP read request (RRQ) to read files outside the intended TFTP root. Because TFTP is unauthenticated and the flaw allows arbitrary file reads, it exposes sensitive files on the host.

7.8 CVSS 2.0 High EPSS 58% · top 0.9% CWE-22 · Path traversal
7.8CVSS 2.0 base score
58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename field of an RRQ operation.

AV:N/AC:L/Au:N/C:C/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityThe flaw is remotely exploitable without authentication, allows arbitrary file reads, has public exploit code, and shows a very high EPSS score, though it is not in KEV.

What it is

The TFTP Server component (version 1.0.0.24) in Ipswitch WhatsUp Gold is vulnerable to directory traversal. A remote attacker can place a .. sequence in the Filename field of a TFTP read request (RRQ) to read files outside the intended TFTP root. Because TFTP is unauthenticated and the flaw allows arbitrary file reads, it exposes sensitive files on the host.

Impact

An attacker can read arbitrary files accessible to the TFTP service, potentially exposing configuration files, credentials, or other sensitive data. There is no write or code execution impact per the CVSS vector, which is confidentiality-only.

Attack surface

Reachable over the network via the TFTP service (UDP port 69 by default) by sending a crafted RRQ with a traversal path in the Filename field. No authentication or user interaction is required, as reflected by the AV:N/AC:L/Au:N vector.

Exploitation

Public exploit code is referenced (Exploit-DB 18189 and secpod.org), and EPSS is high at roughly 0.58 (99th percentile), but the CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record in this dataset.

What to do

  • Patch or upgrade Ipswitch WhatsUp Gold to a version where the TFTP Server traversal is fixed; consult the vendor advisory (HP/HPE doc referenced) for the corrected build.
  • If the TFTP Server component is not required, disable or uninstall it.
  • Restrict network access to the TFTP service (UDP 69) to trusted management hosts only, using firewall or ACL rules.
  • Run the TFTP service with least privilege and in a directory that contains no sensitive files.
  • Monitor for and block traversal patterns such as '..' in TFTP request filenames at the network or application layer.

Detection

  • Inspect TFTP RRQ traffic for filenames containing '..' or absolute paths.
  • Alert on TFTP read requests for files outside the expected TFTP root or for sensitive filenames (e.g., configuration, credential, or system files).
  • Monitor host file access logs for the TFTP service account reading unexpected paths.
  • Watch for TFTP traffic from hosts that do not normally use the service, especially to WhatsUp Gold servers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-4722 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed10.0CVE-2026-34909UniFi OS path traversal allows unauthenticated file accessUniFi OS devices contain a path traversal flaw (CWE-22) that lets a network-reachable attacker read files on the underlying system. Because the expos…KEVEPSS 1.8%analysed6.5CVE-2026-20262Cisco Catalyst SD-WAN Manager path traversal in file uploadCisco Catalyst SD-WAN Manager (formerly vManage) fails to properly validate user-supplied input during a file upload process, allowing path traversal…KEVEPSS 28%analysed8.4CVE-2024-1708ConnectWise ScreenConnect path traversal enabling remote code executionConnectWise ScreenConnect 23.9.7 and earlier contain a path-traversal flaw (CWE-22) that can let an attacker execute remote code or reach confidentia…KEVEPSS 95%analysed

Source: NIST National Vulnerability Database (record CVE-2011-4722), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.