CVE-2024-6671 is a critical SQL Injection vulnerability affecting WhatsUp Gold versions released before 2024.0.0. This flaw allows an unauthenticated attacker to retrieve the encrypted password of the sole configured user. With a CVSS score of 9.8 (Critical), it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. Exploit intelligence indicates public Proof-of-Concept exploits exist, with cybercriminals actively targeting this vulnerability within hours of PoC release, as evidenced by significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 23.1.0, < 24.0CPE matchmatch criteria | cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:* | ||
>= 2023.1.0, < 2024.0.0CPE match | cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.