Vulnerability Description
In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Progress | Whatsup Gold | < 23.1.0 |
Related Weaknesses (CWE)
References
- https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-DecemberVendor Advisory
- https://www.progress.com/network-monitoringProduct
- https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-DecemberVendor Advisory
- https://www.progress.com/network-monitoringProduct
FAQ
What is CVE-2023-6595?
CVE-2023-6595 is a vulnerability with a CVSS score of 7.5 (HIGH). In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential i...
How severe is CVE-2023-6595?
CVE-2023-6595 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6595?
Check the references section above for vendor advisories and patch information. Affected products include: Progress Whatsup Gold.