CVE-2023-6368

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
14/12/2023
Last modified:
16/10/2024

Description

In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate information related to a registered device being monitored by WhatsUp Gold.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:* 23.1.0 (excluding)