Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-6595


In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.


Published

2023-12-14T16:15:54.453

Last Modified

2024-11-21T08:44:10.217

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-306
  • Type: Secondary
    CWE-306

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application progress whatsup_gold < 23.1.0 Yes

References