← Vulnerability feed

Vulnerability record · CVE-2024-5010 · published 25 June 2024

CVE-2024-5010: WhatsUp Gold TestController unauthenticated information disclosure

Progress · Whatsup Gold

WhatsUp Gold versions before 2023.1.3 expose sensitive information through the TestController functionality. A specially crafted unauthenticated HTTP request can trigger the disclosure, making the flaw remotely reachable without credentials. Because WhatsUp Gold is a network monitoring platform, leaked data may aid further intrusion.

7.5 CVSS 3.1 High EPSS 70% · top 0.6% CWE-200 · Information exposure
7.5CVSS 3.1 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality.  A specially crafted unauthenticated HTTP request can lead to a disclosure of sensitive information.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote information disclosure with a high EPSS score and no KEV listing, warranting prompt patching.

What it is

WhatsUp Gold versions before 2023.1.3 expose sensitive information through the TestController functionality. A specially crafted unauthenticated HTTP request can trigger the disclosure, making the flaw remotely reachable without credentials. Because WhatsUp Gold is a network monitoring platform, leaked data may aid further intrusion.

Impact

An attacker gains access to sensitive information returned by the TestController endpoint. The exact data exposed is not specified in the record, so the full scope of the leak cannot be confirmed.

Attack surface

Reachable over the network via HTTP against the TestController functionality; the CVSS vector shows no privileges or user interaction required. No authentication is needed per the description.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at 0.69952 (99.3rd percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade WhatsUp Gold to 2023.1.3 or later per the Progress security bulletin.
  • Restrict network access to the WhatsUp Gold web interface to trusted management networks.
  • Monitor vendor advisories and apply any follow-up patches for the TestController component.
  • Review logs for anomalous unauthenticated requests to TestController endpoints.

Detection

  • Alert on unauthenticated HTTP requests to TestController paths in web server or application logs.
  • Baseline normal TestController traffic and flag unusual request patterns or payloads.
  • Correlate outbound data volume or response anomalies from the WhatsUp Gold host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-5010 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6670Progress WhatsUp Gold SQL Injection Exposes Encrypted PasswordsWhatsUp Gold versions before 2024.0.0 contain a SQL injection flaw (CWE-89) that an unauthenticated attacker can use to retrieve users' encrypted pas…KEVEPSS 93%analysed9.8CVE-2024-4885Progress WhatsUp Gold path traversal enables unauthenticated remote code executionWhatsUp Gold versions before 2023.1.3 contain a path traversal flaw in WhatsUp.ExportUtilities.Export.GetFileWithoutZip that allows unauthenticated a…KEVEPSS 99%analysed9.8CVE-2024-46909WhatsUp Gold pre-2024.0.1 remote code execution flawWhatsUp Gold versions before 2024.0.1 contain a flaw that lets a remote, unauthenticated attacker execute code in the context of the service account.…EPSS 49%analysed9.8CVE-2024-6671Progress whatsup gold sql injection vulnerabilityIn WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an …EPSS 19%9.8CVE-2024-4883WhatsUp Gold NmApi.exe unauthenticated remote code executionProgress WhatsUp Gold versions released before 2023.1.3 contain a remote code execution flaw reachable through NmApi.exe. An unauthenticated attacker…EPSS 65%analysed9.8CVE-2024-4884Progress whatsup gold command injection vulnerabilityIn WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.…EPSS 24%9.8CVE-2018-8938Progress whatsup gold code injection vulnerabilityA Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially cr…EPSS 2.3%9.8CVE-2018-8939Progress whatsup gold server-side request forgery (ssrf) vulnerabilityAn SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2024-5010), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.