Vulnerability record · CVE-2024-46909 · published 2 December 2024
CVE-2024-46909: WhatsUp Gold pre-2024.0.1 remote code execution flaw
Progress · Whatsup Gold
WhatsUp Gold versions before 2024.0.1 contain a flaw that lets a remote, unauthenticated attacker execute code in the context of the service account. The record does not specify the exact root cause; CWE entries point to path traversal and related input-handling issues, but NVD also lists insufficient information. Because it is network-reachable with no credentials required, it is a serious pre-auth risk for exposed installations.
Description
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityPre-auth remote code execution with a 9.8 CVSS score and high EPSS makes this an urgent patch for any exposed WhatsUp Gold instance.
What it is
WhatsUp Gold versions before 2024.0.1 contain a flaw that lets a remote, unauthenticated attacker execute code in the context of the service account. The record does not specify the exact root cause; CWE entries point to path traversal and related input-handling issues, but NVD also lists insufficient information. Because it is network-reachable with no credentials required, it is a serious pre-auth risk for exposed installations.
Impact
An attacker gains arbitrary code execution as the WhatsUp Gold service account, which typically carries broad privileges over the monitoring server and its managed data. That can lead to full compromise of the host and any credentials or network access the service holds.
Attack surface
Reached over the network via the WhatsUp Gold web interface or service endpoints, per the CVSS vector AV:N/PR:N/UI:N. No authentication and no user interaction are required, so any internet- or network-exposed instance is directly reachable.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware association is recorded in this entry. EPSS is high at roughly 0.49 (98.8th percentile), indicating elevated predicted exploitation likelihood, but the record provides no confirmed in-the-wild activity.
What to do
- Upgrade WhatsUp Gold to 2024.0.1 or later per the Progress security bulletin.
- Restrict network access to the WhatsUp Gold web interface and management ports to trusted hosts only.
- Run the WhatsUp Gold service under a least-privilege account to limit post-exploitation reach.
- Monitor vendor advisories and release notes for follow-up fixes or updated guidance.
Detection
- Review web and service logs for anomalous requests to WhatsUp Gold endpoints, especially path traversal patterns such as ../ sequences.
- Alert on unexpected child processes or command execution spawned by the WhatsUp Gold service account.
- Baseline and monitor outbound connections from the WhatsUp Gold server for signs of post-exploitation activity.
- Audit authentication logs for unauthenticated access attempts against management interfaces.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-46909 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-46909), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.