CVE-2023-6368
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
14/12/2023
Last modified:
16/10/2024
Description
In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate information related to a registered device being monitored by WhatsUp Gold.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:* | 23.1.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



