RULE(RULE ID:338270)

Rule General Information
Release Date: 2024-07-23
Rule Name: WhatsUp Gold Remote Code Execution Vulnerability (CVE-2024-4885)
Severity:
CVE ID:
Rule Protection Details
Description: In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024
https://www.progress.com/network-monitoring
Solutions
Refer to the announcement or patch by the vendor: https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024