Vulnerability Description
In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate information related to a registered device being monitored by WhatsUp Gold.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Progress | Whatsup Gold | < 23.1.0 |
Related Weaknesses (CWE)
References
- https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-DecemberVendor Advisory
- https://www.progress.com/network-monitoringProduct
- https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-DecemberVendor Advisory
- https://www.progress.com/network-monitoringProduct
FAQ
What is CVE-2023-6368?
CVE-2023-6368 is a vulnerability with a CVSS score of 5.9 (MEDIUM). In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate information related to...
How severe is CVE-2023-6368?
CVE-2023-6368 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6368?
Check the references section above for vendor advisories and patch information. Affected products include: Progress Whatsup Gold.