Vulnerability record · CVE-2024-4883 · published 25 June 2024
CVE-2024-4883: WhatsUp Gold NmApi.exe unauthenticated remote code execution
Progress · Whatsup Gold
Progress WhatsUp Gold versions released before 2023.1.3 contain a remote code execution flaw reachable through NmApi.exe. An unauthenticated attacker can execute code as a service account, which makes this a severe pre-auth issue for any internet- or network-exposed deployment.
Description
In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, plus a very high EPSS score, makes this an urgent pre-auth RCE.
What it is
Progress WhatsUp Gold versions released before 2023.1.3 contain a remote code execution flaw reachable through NmApi.exe. An unauthenticated attacker can execute code as a service account, which makes this a severe pre-auth issue for any internet- or network-exposed deployment.
Impact
An attacker gains arbitrary code execution with the privileges of the WhatsUp Gold service account, allowing full compromise of the monitoring server and likely lateral movement into monitored infrastructure.
Attack surface
Reached over the network via the NmApi.exe component; the CVSS vector shows no privileges required and no user interaction, so it is exploitable pre-authentication.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is 0.64535 (99.2nd percentile), indicating high predicted exploitation activity.
What to do
- Upgrade WhatsUp Gold to 2023.1.3 or later per the Progress security bulletin.
- Restrict network access to the WhatsUp Gold server and NmApi.exe ports to trusted management networks only.
- Run the WhatsUp Gold service under a least-privilege account rather than a highly privileged service account.
- Monitor Progress advisories for updated guidance and apply any follow-up patches promptly.
Detection
- Monitor for unexpected child processes spawned by NmApi.exe, especially command shells or scripting interpreters.
- Alert on anomalous network connections to the WhatsUp Gold host from untrusted sources.
- Review WhatsUp Gold and Windows event logs for unusual service account activity or process creation around NmApi.exe.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-4883 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-4883), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.