V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2024-12108
CVE
Critical

In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.

CVSS
9.6
Critical
EPSS
0.07
p93
Published
2024-01-01
Updated
2024-01-01
Description

In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.

Tags · CWE
CWE-290
CAPEC-21
CAPEC-22
CAPEC-59
CAPEC-60
CAPEC-94
CAPEC-459
CAPEC-461
CAPEC-473
CAPEC-476
CAPEC-667
Affected products
Whatsup_gold
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.068 · p93
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-473 · CWE-290
└ via CAPEC-21 · CWE-290
└ via CAPEC-60 · CWE-290
└ via CAPEC-21 · CWE-290
└ via CAPEC-21 · CWE-290
└ via CAPEC-60 · CWE-290
└ via CAPEC-473 · CWE-290
└ via CAPEC-94 · CWE-290
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
whatsup_gold*Tracked
Source databases
CVE