← Back to browse · API

CVE-2024-8785

Severity
CRITICAL
CVSS
9.8
EPSS
0.09741
Risk score
42.61
CISA KEV
No
PoC
No
Published
2024-12-02
Modified
2024-12-02
First seen
2026-08-07
Aliases
EUVD-2024-49604, GHSA-5WJJ-XCHX-55WF
Products
Progress Software Corporation:WhatsUp Gold 2023.1.0 <2024.0.1
Sources
euvd EUVD-2024-49604

Description

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.

References