Vulnerability Description
A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially crafted SNMP MIB file that could allow them to execute arbitrary commands and code on the WhatsUp Gold server.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Progress | Whatsup Gold | < 18.0 |
Related Weaknesses (CWE)
References
- https://docs.ipswitch.com/NM/WhatsUpGold2018/01_ReleaseNotes/index.htmRelease NotesVendor Advisory
- https://docs.ipswitch.com/NM/WhatsUpGold2018/01_ReleaseNotes/index.htmRelease NotesVendor Advisory
FAQ
What is CVE-2018-8938?
CVE-2018-8938 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially crafted SNMP MIB file that could allow them to execut...
How severe is CVE-2018-8938?
CVE-2018-8938 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-8938?
Check the references section above for vendor advisories and patch information. Affected products include: Progress Whatsup Gold.