Vulnerability record · CVE-2022-29847 · published 11 May 2022
CVE-2022-29847: WhatsUp Gold unauthenticated SSRF relays user credentials
Progress · Whatsup Gold
Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1 and 22.0.0 exposes an API transaction that an unauthenticated attacker can invoke to relay encrypted WhatsUp Gold user credentials to an arbitrary host. Because the flaw is a server-side request forgery, the product itself acts as the relay, which makes credential theft possible without any prior access to the application.
Description
In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable credential relay with a 7.5 CVSS score and very high EPSS, though no confirmed in-the-wild exploitation is documented.
What it is
Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1 and 22.0.0 exposes an API transaction that an unauthenticated attacker can invoke to relay encrypted WhatsUp Gold user credentials to an arbitrary host. Because the flaw is a server-side request forgery, the product itself acts as the relay, which makes credential theft possible without any prior access to the application.
Impact
An attacker can cause the server to send encrypted WhatsUp Gold user credentials to a host they control, enabling offline cracking or replay of those credentials and potential lateral movement into monitored infrastructure.
Attack surface
Reachable over the network through the WhatsUp Gold API with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not specify which endpoint or parameter is involved.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is 0.5762 (99th percentile), indicating a high modeled likelihood of exploitation activity. The only references are the vendor advisory and product page.
What to do
- Apply the fix from the Progress WhatsUp Gold Critical Product Alert (May 2022) for the affected 21.0.0-21.1.1 and 22.0.0 releases.
- Restrict network access to the WhatsUp Gold web/API interface to trusted management networks and block outbound traffic from the server to untrusted hosts.
- Rotate WhatsUp Gold user credentials and any credentials the product stores, since encrypted credentials may have been relayed.
- Monitor and log API transactions for requests that trigger outbound connections to unexpected destinations.
Detection
- Review WhatsUp Gold server logs and network flow data for outbound connections from the product to unfamiliar external or internal hosts.
- Alert on API calls to WhatsUp Gold endpoints from unauthenticated or unexpected source addresses.
- Hunt for repeated or anomalous outbound requests originating from the WhatsUp Gold host that do not match normal monitoring behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-29847 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-29847), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.