Vulnerability record · CVE-2011-4722 · published 28 December 2014
CVE-2011-4722: Ipswitch WhatsUp Gold TFTP Server directory traversal file read
Ipswitch · Tftp Server
The TFTP Server component (version 1.0.0.24) in Ipswitch WhatsUp Gold is vulnerable to directory traversal. A remote attacker can place a .. sequence in the Filename field of a TFTP read request (RRQ) to read files outside the intended TFTP root. Because TFTP is unauthenticated and the flaw allows arbitrary file reads, it exposes sensitive files on the host.
Description
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename field of an RRQ operation.
AV:N/AC:L/Au:N/C:C/I:N/A:N
Automated analysis
high priorityThe flaw is remotely exploitable without authentication, allows arbitrary file reads, has public exploit code, and shows a very high EPSS score, though it is not in KEV.
What it is
The TFTP Server component (version 1.0.0.24) in Ipswitch WhatsUp Gold is vulnerable to directory traversal. A remote attacker can place a .. sequence in the Filename field of a TFTP read request (RRQ) to read files outside the intended TFTP root. Because TFTP is unauthenticated and the flaw allows arbitrary file reads, it exposes sensitive files on the host.
Impact
An attacker can read arbitrary files accessible to the TFTP service, potentially exposing configuration files, credentials, or other sensitive data. There is no write or code execution impact per the CVSS vector, which is confidentiality-only.
Attack surface
Reachable over the network via the TFTP service (UDP port 69 by default) by sending a crafted RRQ with a traversal path in the Filename field. No authentication or user interaction is required, as reflected by the AV:N/AC:L/Au:N vector.
Exploitation
Public exploit code is referenced (Exploit-DB 18189 and secpod.org), and EPSS is high at roughly 0.58 (99th percentile), but the CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record in this dataset.
What to do
- Patch or upgrade Ipswitch WhatsUp Gold to a version where the TFTP Server traversal is fixed; consult the vendor advisory (HP/HPE doc referenced) for the corrected build.
- If the TFTP Server component is not required, disable or uninstall it.
- Restrict network access to the TFTP service (UDP 69) to trusted management hosts only, using firewall or ACL rules.
- Run the TFTP service with least privilege and in a directory that contains no sensitive files.
- Monitor for and block traversal patterns such as '..' in TFTP request filenames at the network or application layer.
Detection
- Inspect TFTP RRQ traffic for filenames containing '..' or absolute paths.
- Alert on TFTP read requests for files outside the expected TFTP root or for sensitive filenames (e.g., configuration, credential, or system files).
- Monitor host file access logs for the TFTP service account reading unexpected paths.
- Watch for TFTP traffic from hosts that do not normally use the service, especially to WhatsUp Gold servers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-4722 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-4722), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.