vulnerability

Progress WhatsUp Gold: CVE-2023-6595: Missing Authentication for Critical Function

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
Dec 14, 2023
Added
Jul 9, 2025
Modified
Jul 9, 2025

Description

In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.

Solution

progress-whatsup-gold-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.