Vulnerability record · CVE-2024-5011 · published 25 June 2024
CVE-2024-5011: WhatsUp Gold unauthenticated HTTP request causes denial of service
Progress · Whatsup Gold
WhatsUp Gold versions before 2023.1.3 contain an uncontrolled resource consumption flaw (CWE-400). A specially crafted unauthenticated HTTP request to the TestController Chart functionality can exhaust resources and cause denial of service. The vendor has released a fixed version, so exposure is limited to unpatched deployments.
Description
In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTTP request to the TestController Chart functionality can lead to denial of service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated network-reachable denial of service with a high EPSS score, though no confirmed in-the-wild exploitation or KEV listing.
What it is
WhatsUp Gold versions before 2023.1.3 contain an uncontrolled resource consumption flaw (CWE-400). A specially crafted unauthenticated HTTP request to the TestController Chart functionality can exhaust resources and cause denial of service. The vendor has released a fixed version, so exposure is limited to unpatched deployments.
Impact
An unauthenticated attacker can degrade or take down the WhatsUp Gold monitoring service, disrupting network visibility and alerting. There is no confidentiality or integrity impact per the CVSS vector; only availability is affected.
Attack surface
Reachable over the network via HTTP to the TestController Chart endpoint, with no authentication and no user interaction required (AV:N/PR:N/UI:N). Any host that can reach the web interface can attempt it.
Exploitation
Not listed in CISA KEV and no public exploit tag is present in the references, but EPSS is high at roughly 0.47 (98.8th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade WhatsUp Gold to 2023.1.3 or later per the Progress security bulletin
- Restrict network access to the WhatsUp Gold web interface to trusted management networks
- Rate-limit or filter requests to the TestController Chart endpoint at the reverse proxy or WAF
- Monitor resource usage on WhatsUp Gold hosts and alert on abnormal spikes
- Apply the vendor advisory guidance and verify the deployed version after patching
Detection
- Alert on abnormal CPU, memory or connection spikes on WhatsUp Gold servers
- Log and review HTTP requests to the TestController Chart endpoint, especially from untrusted sources
- Detect repeated or malformed requests to that endpoint from a single source
- Correlate service unavailability events with inbound HTTP request patterns
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024 | Vendor Advisory |
| https://www.progress.com/network-monitoring | Product |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1934 | Third Party Advisory |
| https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024 | Vendor Advisory |
| https://www.progress.com/network-monitoring | Product |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1934 | Third Party Advisory |
Track CVE-2024-5011 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-5011), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.