CVE-2022-29845
 
Severity Score
6.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read the contents of a local file.
En Progress Ipswitch WhatsUp Gold versiones 21.1.0 hasta 21.1.1, y 22.0.0, es posible que un usuario autenticado invoque una transacción API que le permita leer el contenido de un archivo local
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-04-27 CVE Reserved
- 2022-05-11 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-829: Inclusion of Functionality from Untrusted Control Sphere
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.progress.com/network-monitoring | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://community.progress.com/s/article/WhatsUp-Gold-Critical-Product-Alert-May-2022 | 2022-05-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ipswitch Search vendor "Ipswitch" | Whatsup Gold Search vendor "Ipswitch" for product "Whatsup Gold" | 21.1.0 Search vendor "Ipswitch" for product "Whatsup Gold" and version "21.1.0" | - |
Affected
| ||||||
Ipswitch Search vendor "Ipswitch" | Whatsup Gold Search vendor "Ipswitch" for product "Whatsup Gold" | 21.1.1 Search vendor "Ipswitch" for product "Whatsup Gold" and version "21.1.1" | - |
Affected
| ||||||
Ipswitch Search vendor "Ipswitch" | Whatsup Gold Search vendor "Ipswitch" for product "Whatsup Gold" | 22.0.0 Search vendor "Ipswitch" for product "Whatsup Gold" and version "22.0.0" | - |
Affected
|