← Vulnerability feed

Vulnerability record · CVE-2022-29847 · published 11 May 2022

CVE-2022-29847: WhatsUp Gold unauthenticated SSRF relays user credentials

Progress · Whatsup Gold

Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1 and 22.0.0 exposes an API transaction that an unauthenticated attacker can invoke to relay encrypted WhatsUp Gold user credentials to an arbitrary host. Because the flaw is a server-side request forgery, the product itself acts as the relay, which makes credential theft possible without any prior access to the application.

7.5 CVSS 3.1 High EPSS 58% · top 0.9% CWE-918 · Server-side request forgery (SSRF)
7.5CVSS 3.1 base score, v2 5.0
58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable credential relay with a 7.5 CVSS score and very high EPSS, though no confirmed in-the-wild exploitation is documented.

What it is

Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1 and 22.0.0 exposes an API transaction that an unauthenticated attacker can invoke to relay encrypted WhatsUp Gold user credentials to an arbitrary host. Because the flaw is a server-side request forgery, the product itself acts as the relay, which makes credential theft possible without any prior access to the application.

Impact

An attacker can cause the server to send encrypted WhatsUp Gold user credentials to a host they control, enabling offline cracking or replay of those credentials and potential lateral movement into monitored infrastructure.

Attack surface

Reachable over the network through the WhatsUp Gold API with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not specify which endpoint or parameter is involved.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is 0.5762 (99th percentile), indicating a high modeled likelihood of exploitation activity. The only references are the vendor advisory and product page.

What to do

  • Apply the fix from the Progress WhatsUp Gold Critical Product Alert (May 2022) for the affected 21.0.0-21.1.1 and 22.0.0 releases.
  • Restrict network access to the WhatsUp Gold web/API interface to trusted management networks and block outbound traffic from the server to untrusted hosts.
  • Rotate WhatsUp Gold user credentials and any credentials the product stores, since encrypted credentials may have been relayed.
  • Monitor and log API transactions for requests that trigger outbound connections to unexpected destinations.

Detection

  • Review WhatsUp Gold server logs and network flow data for outbound connections from the product to unfamiliar external or internal hosts.
  • Alert on API calls to WhatsUp Gold endpoints from unauthenticated or unexpected source addresses.
  • Hunt for repeated or anomalous outbound requests originating from the WhatsUp Gold host that do not match normal monitoring behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-29847 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6670Progress WhatsUp Gold SQL Injection Exposes Encrypted PasswordsWhatsUp Gold versions before 2024.0.0 contain a SQL injection flaw (CWE-89) that an unauthenticated attacker can use to retrieve users' encrypted pas…KEVEPSS 93%analysed9.8CVE-2024-4885Progress WhatsUp Gold path traversal enables unauthenticated remote code executionWhatsUp Gold versions before 2023.1.3 contain a path traversal flaw in WhatsUp.ExportUtilities.Export.GetFileWithoutZip that allows unauthenticated a…KEVEPSS 99%analysed9.8CVE-2024-46909WhatsUp Gold pre-2024.0.1 remote code execution flawWhatsUp Gold versions before 2024.0.1 contain a flaw that lets a remote, unauthenticated attacker execute code in the context of the service account.…EPSS 49%analysed9.8CVE-2024-6671Progress whatsup gold sql injection vulnerabilityIn WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an …EPSS 19%9.8CVE-2024-4883WhatsUp Gold NmApi.exe unauthenticated remote code executionProgress WhatsUp Gold versions released before 2023.1.3 contain a remote code execution flaw reachable through NmApi.exe. An unauthenticated attacker…EPSS 65%analysed9.8CVE-2024-4884Progress whatsup gold command injection vulnerabilityIn WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.…EPSS 24%9.8CVE-2018-8938Progress whatsup gold code injection vulnerabilityA Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially cr…EPSS 2.3%9.8CVE-2018-8939Progress whatsup gold server-side request forgery (ssrf) vulnerabilityAn SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2022-29847), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.