← Vulnerability feed

Vulnerability record · CVE-2024-46909 · published 2 December 2024

CVE-2024-46909: WhatsUp Gold pre-2024.0.1 remote code execution flaw

Progress · Whatsup Gold

WhatsUp Gold versions before 2024.0.1 contain a flaw that lets a remote, unauthenticated attacker execute code in the context of the service account. The record does not specify the exact root cause; CWE entries point to path traversal and related input-handling issues, but NVD also lists insufficient information. Because it is network-reachable with no credentials required, it is a serious pre-auth risk for exposed installations.

9.8 CVSS 3.1 Critical EPSS 49% · top 1.2% CWE-16 · CWE-16CWE-22 · Path traversal
9.8CVSS 3.1 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityPre-auth remote code execution with a 9.8 CVSS score and high EPSS makes this an urgent patch for any exposed WhatsUp Gold instance.

What it is

WhatsUp Gold versions before 2024.0.1 contain a flaw that lets a remote, unauthenticated attacker execute code in the context of the service account. The record does not specify the exact root cause; CWE entries point to path traversal and related input-handling issues, but NVD also lists insufficient information. Because it is network-reachable with no credentials required, it is a serious pre-auth risk for exposed installations.

Impact

An attacker gains arbitrary code execution as the WhatsUp Gold service account, which typically carries broad privileges over the monitoring server and its managed data. That can lead to full compromise of the host and any credentials or network access the service holds.

Attack surface

Reached over the network via the WhatsUp Gold web interface or service endpoints, per the CVSS vector AV:N/PR:N/UI:N. No authentication and no user interaction are required, so any internet- or network-exposed instance is directly reachable.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware association is recorded in this entry. EPSS is high at roughly 0.49 (98.8th percentile), indicating elevated predicted exploitation likelihood, but the record provides no confirmed in-the-wild activity.

What to do

  • Upgrade WhatsUp Gold to 2024.0.1 or later per the Progress security bulletin.
  • Restrict network access to the WhatsUp Gold web interface and management ports to trusted hosts only.
  • Run the WhatsUp Gold service under a least-privilege account to limit post-exploitation reach.
  • Monitor vendor advisories and release notes for follow-up fixes or updated guidance.

Detection

  • Review web and service logs for anomalous requests to WhatsUp Gold endpoints, especially path traversal patterns such as ../ sequences.
  • Alert on unexpected child processes or command execution spawned by the WhatsUp Gold service account.
  • Baseline and monitor outbound connections from the WhatsUp Gold server for signs of post-exploitation activity.
  • Audit authentication logs for unauthenticated access attempts against management interfaces.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-46909 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6670Progress WhatsUp Gold SQL Injection Exposes Encrypted PasswordsWhatsUp Gold versions before 2024.0.0 contain a SQL injection flaw (CWE-89) that an unauthenticated attacker can use to retrieve users' encrypted pas…KEVEPSS 93%analysed9.8CVE-2024-4885Progress WhatsUp Gold path traversal enables unauthenticated remote code executionWhatsUp Gold versions before 2023.1.3 contain a path traversal flaw in WhatsUp.ExportUtilities.Export.GetFileWithoutZip that allows unauthenticated a…KEVEPSS 99%analysed9.8CVE-2024-6671Progress whatsup gold sql injection vulnerabilityIn WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an …EPSS 19%9.8CVE-2024-4883WhatsUp Gold NmApi.exe unauthenticated remote code executionProgress WhatsUp Gold versions released before 2023.1.3 contain a remote code execution flaw reachable through NmApi.exe. An unauthenticated attacker…EPSS 65%analysed9.8CVE-2024-4884Progress whatsup gold command injection vulnerabilityIn WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.…EPSS 24%9.8CVE-2018-8938Progress whatsup gold code injection vulnerabilityA Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially cr…EPSS 2.3%9.8CVE-2018-8939Progress whatsup gold server-side request forgery (ssrf) vulnerabilityAn SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the…EPSS 1.4%9.8CVE-2018-5777Progress whatsup gold vulnerabilityAn issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a misconfiguration in the TFTP s…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2024-46909), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.