RULE(RULE ID:338408)

Rule General Information
Release Date: 2024-09-10
Rule Name: WhatsUp Gold SQL Injection Vulnerability (CVE-2024-6670)
Severity:
CVE ID:
Rule Protection Details
Description: In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2024
https://www.progress.com/network-monitoring
Solutions
Refer to the announcement or patch by the vendor: https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2024