← Vulnerability feed

Vulnerability record · CVE-2024-5011 · published 25 June 2024

CVE-2024-5011: WhatsUp Gold unauthenticated HTTP request causes denial of service

Progress · Whatsup Gold

WhatsUp Gold versions before 2023.1.3 contain an uncontrolled resource consumption flaw (CWE-400). A specially crafted unauthenticated HTTP request to the TestController Chart functionality can exhaust resources and cause denial of service. The vendor has released a fixed version, so exposure is limited to unpatched deployments.

7.5 CVSS 3.1 High EPSS 47% · top 1.2% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.1 base score
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTTP request to the TestController Chart functionality can lead to denial of service.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityUnauthenticated network-reachable denial of service with a high EPSS score, though no confirmed in-the-wild exploitation or KEV listing.

What it is

WhatsUp Gold versions before 2023.1.3 contain an uncontrolled resource consumption flaw (CWE-400). A specially crafted unauthenticated HTTP request to the TestController Chart functionality can exhaust resources and cause denial of service. The vendor has released a fixed version, so exposure is limited to unpatched deployments.

Impact

An unauthenticated attacker can degrade or take down the WhatsUp Gold monitoring service, disrupting network visibility and alerting. There is no confidentiality or integrity impact per the CVSS vector; only availability is affected.

Attack surface

Reachable over the network via HTTP to the TestController Chart endpoint, with no authentication and no user interaction required (AV:N/PR:N/UI:N). Any host that can reach the web interface can attempt it.

Exploitation

Not listed in CISA KEV and no public exploit tag is present in the references, but EPSS is high at roughly 0.47 (98.8th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Upgrade WhatsUp Gold to 2023.1.3 or later per the Progress security bulletin
  • Restrict network access to the WhatsUp Gold web interface to trusted management networks
  • Rate-limit or filter requests to the TestController Chart endpoint at the reverse proxy or WAF
  • Monitor resource usage on WhatsUp Gold hosts and alert on abnormal spikes
  • Apply the vendor advisory guidance and verify the deployed version after patching

Detection

  • Alert on abnormal CPU, memory or connection spikes on WhatsUp Gold servers
  • Log and review HTTP requests to the TestController Chart endpoint, especially from untrusted sources
  • Detect repeated or malformed requests to that endpoint from a single source
  • Correlate service unavailability events with inbound HTTP request patterns

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-5011 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6670Progress WhatsUp Gold SQL Injection Exposes Encrypted PasswordsWhatsUp Gold versions before 2024.0.0 contain a SQL injection flaw (CWE-89) that an unauthenticated attacker can use to retrieve users' encrypted pas…KEVEPSS 93%analysed9.8CVE-2024-4885Progress WhatsUp Gold path traversal enables unauthenticated remote code executionWhatsUp Gold versions before 2023.1.3 contain a path traversal flaw in WhatsUp.ExportUtilities.Export.GetFileWithoutZip that allows unauthenticated a…KEVEPSS 99%analysed9.8CVE-2024-46909WhatsUp Gold pre-2024.0.1 remote code execution flawWhatsUp Gold versions before 2024.0.1 contain a flaw that lets a remote, unauthenticated attacker execute code in the context of the service account.…EPSS 49%analysed9.8CVE-2024-6671Progress whatsup gold sql injection vulnerabilityIn WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an …EPSS 19%9.8CVE-2024-4883WhatsUp Gold NmApi.exe unauthenticated remote code executionProgress WhatsUp Gold versions released before 2023.1.3 contain a remote code execution flaw reachable through NmApi.exe. An unauthenticated attacker…EPSS 65%analysed9.8CVE-2024-4884Progress whatsup gold command injection vulnerabilityIn WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.…EPSS 24%9.8CVE-2018-8938Progress whatsup gold code injection vulnerabilityA Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially cr…EPSS 2.3%9.8CVE-2018-8939Progress whatsup gold server-side request forgery (ssrf) vulnerabilityAn SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2024-5011), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.