Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-6368


In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate information related to a registered device being monitored by WhatsUp Gold.


Published

2023-12-14T16:15:54.103

Last Modified

2024-11-21T08:43:43.327

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-306
  • Type: Secondary
    CWE-306

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application progress whatsup_gold < 23.1.0 Yes

References