← All CVEs

CVE-2022-29847

high · 7.5

In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host.

7.5
CVSS
57.6%
EPSS (exploit prob.)
99th
EPSS percentile
2022-05-11
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-918

Affected products

VendorProductAffected versions
progresswhatsup_gold>= 21.0.0, <= 21.1.1
progresswhatsup_gold22.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-29847