Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-5016


In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as SYSTEM.  The vulnerability exists in the main message processing routines NmDistributed.DistributedServiceBehavior.OnMessage for server and NmDistributed.DistributedClient.OnMessage for clients.


Published

2024-06-25T21:16:01.163

Last Modified

2024-11-21T09:46:47.320

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-502
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application progress whatsup_gold < 23.1.0 Yes
Application progress whatsup_gold 23.1.0 Yes

References