← Vulnerability feed

Vulnerability record · CVE-2024-4883 · published 25 June 2024

CVE-2024-4883: WhatsUp Gold NmApi.exe unauthenticated remote code execution

Progress · Whatsup Gold

Progress WhatsUp Gold versions released before 2023.1.3 contain a remote code execution flaw reachable through NmApi.exe. An unauthenticated attacker can execute code as a service account, which makes this a severe pre-auth issue for any internet- or network-exposed deployment.

9.8 CVSS 3.1 Critical EPSS 65% · top 0.8% CWE-77 · Command injectionCWE-78 · OS command injection
9.8CVSS 3.1 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, plus a very high EPSS score, makes this an urgent pre-auth RCE.

What it is

Progress WhatsUp Gold versions released before 2023.1.3 contain a remote code execution flaw reachable through NmApi.exe. An unauthenticated attacker can execute code as a service account, which makes this a severe pre-auth issue for any internet- or network-exposed deployment.

Impact

An attacker gains arbitrary code execution with the privileges of the WhatsUp Gold service account, allowing full compromise of the monitoring server and likely lateral movement into monitored infrastructure.

Attack surface

Reached over the network via the NmApi.exe component; the CVSS vector shows no privileges required and no user interaction, so it is exploitable pre-authentication.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is 0.64535 (99.2nd percentile), indicating high predicted exploitation activity.

What to do

  • Upgrade WhatsUp Gold to 2023.1.3 or later per the Progress security bulletin.
  • Restrict network access to the WhatsUp Gold server and NmApi.exe ports to trusted management networks only.
  • Run the WhatsUp Gold service under a least-privilege account rather than a highly privileged service account.
  • Monitor Progress advisories for updated guidance and apply any follow-up patches promptly.

Detection

  • Monitor for unexpected child processes spawned by NmApi.exe, especially command shells or scripting interpreters.
  • Alert on anomalous network connections to the WhatsUp Gold host from untrusted sources.
  • Review WhatsUp Gold and Windows event logs for unusual service account activity or process creation around NmApi.exe.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-4883 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6670Progress WhatsUp Gold SQL Injection Exposes Encrypted PasswordsWhatsUp Gold versions before 2024.0.0 contain a SQL injection flaw (CWE-89) that an unauthenticated attacker can use to retrieve users' encrypted pas…KEVEPSS 93%analysed9.8CVE-2024-4885Progress WhatsUp Gold path traversal enables unauthenticated remote code executionWhatsUp Gold versions before 2023.1.3 contain a path traversal flaw in WhatsUp.ExportUtilities.Export.GetFileWithoutZip that allows unauthenticated a…KEVEPSS 99%analysed9.8CVE-2024-46909WhatsUp Gold pre-2024.0.1 remote code execution flawWhatsUp Gold versions before 2024.0.1 contain a flaw that lets a remote, unauthenticated attacker execute code in the context of the service account.…EPSS 49%analysed9.8CVE-2024-6671Progress whatsup gold sql injection vulnerabilityIn WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an …EPSS 19%9.8CVE-2024-4884Progress whatsup gold command injection vulnerabilityIn WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.…EPSS 24%9.8CVE-2018-8938Progress whatsup gold code injection vulnerabilityA Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially cr…EPSS 2.3%9.8CVE-2018-8939Progress whatsup gold server-side request forgery (ssrf) vulnerabilityAn SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the…EPSS 1.4%9.8CVE-2018-5777Progress whatsup gold vulnerabilityAn issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a misconfiguration in the TFTP s…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2024-4883), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.