← Vulnerability feed

Vulnerability record · CVE-2024-6670 · published 29 August 2024

CVE-2024-6670: Progress WhatsUp Gold SQL Injection Exposes Encrypted Passwords

Progress · Whatsup Gold

WhatsUp Gold versions before 2024.0.0 contain a SQL injection flaw (CWE-89) that an unauthenticated attacker can use to retrieve users' encrypted passwords. Because the vulnerable component is network-reachable and requires no credentials, it is a high-value initial access vector for a widely deployed network monitoring product.

9.8 CVSS 3.1 Critical CISA KEV since 16 Sep 2024 Known ransomware use EPSS 93% · top 0.2% CWE-89 · SQL injection
9.8CVSS 3.1 base score
93%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network exploitation, confirmed active exploitation with ransomware use, and CISA KEV listing make this an urgent patching priority.

What it is

WhatsUp Gold versions before 2024.0.0 contain a SQL injection flaw (CWE-89) that an unauthenticated attacker can use to retrieve users' encrypted passwords. Because the vulnerable component is network-reachable and requires no credentials, it is a high-value initial access vector for a widely deployed network monitoring product.

Impact

An attacker gains access to encrypted user passwords, which can be cracked offline or reused to move laterally into the monitoring platform and the infrastructure it manages. Successful exploitation can lead to full compromise of the WhatsUp Gold host and connected systems.

Attack surface

Reachable over the network via the WhatsUp Gold web interface; the CVSS vector (AV:N/PR:N/UI:N) confirms no authentication and no user interaction are required.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2024-09-16 with known ransomware campaign use, and EPSS gives a 30-day exploitation probability of 0.93 (99.8th percentile), indicating active exploitation in the wild.

What to do

  • Upgrade WhatsUp Gold to 2024.0.0 or later immediately; this is the only complete fix.
  • If immediate upgrade is not possible, apply the vendor mitigations in the Progress August 2024 security bulletin or discontinue use of the product per CISA guidance.
  • Restrict network access to the WhatsUp Gold web interface to trusted management networks and block it from the public internet.
  • Rotate all WhatsUp Gold user credentials and any credentials stored or managed by the platform, since encrypted passwords may have been exposed.
  • Monitor for and investigate any signs of lateral movement or ransomware activity originating from the WhatsUp Gold host.

Detection

  • Review WhatsUp Gold web server and application logs for SQL injection patterns or anomalous database queries, especially from unauthenticated sessions.
  • Hunt for unusual outbound connections or data transfers from the WhatsUp Gold host that could indicate password exfiltration.
  • Audit authentication logs for successful logins using WhatsUp Gold accounts from unexpected source IPs or at unusual times.
  • Check for indicators of compromise associated with known ransomware campaigns that have exploited this CVE.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-6670 to the Known Exploited Vulnerabilities catalog on 16 September 2024 as "Progress WhatsUp Gold SQL Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 7 October 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-6670 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-4885Progress WhatsUp Gold path traversal enables unauthenticated remote code executionWhatsUp Gold versions before 2023.1.3 contain a path traversal flaw in WhatsUp.ExportUtilities.Export.GetFileWithoutZip that allows unauthenticated a…KEVEPSS 99%analysed9.8CVE-2024-46909WhatsUp Gold pre-2024.0.1 remote code execution flawWhatsUp Gold versions before 2024.0.1 contain a flaw that lets a remote, unauthenticated attacker execute code in the context of the service account.…EPSS 49%analysed9.8CVE-2024-6671Progress whatsup gold sql injection vulnerabilityIn WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an …EPSS 19%9.8CVE-2024-4883WhatsUp Gold NmApi.exe unauthenticated remote code executionProgress WhatsUp Gold versions released before 2023.1.3 contain a remote code execution flaw reachable through NmApi.exe. An unauthenticated attacker…EPSS 65%analysed9.8CVE-2024-4884Progress whatsup gold command injection vulnerabilityIn WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.…EPSS 24%9.8CVE-2018-8938Progress whatsup gold code injection vulnerabilityA Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially cr…EPSS 2.3%9.8CVE-2018-8939Progress whatsup gold server-side request forgery (ssrf) vulnerabilityAn SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the…EPSS 1.4%9.8CVE-2018-5777Progress whatsup gold vulnerabilityAn issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a misconfiguration in the TFTP s…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2024-6670), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.