WhatsUp Gold, a widely used network monitoring software, recently identified six critical vulnerabilities that could allow attackers to access unauthorized networks.
The vulnerabilities affect versions below 24.0.1, and users are urged to upgrade immediately to ensure their systems are secure.
The vulnerabilities were disclosed in the WhatsUp Gold Security Bulletin for September 2024.
According to the researchers, these security flaws can potentially enable attackers to exploit the system and access sensitive network information without authorization.
Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Free Registration
The vulnerabilities have been assigned Common Vulnerabilities and Exposures (CVE) identifiers, each with a high Common Vulnerability Scoring System (CVSS) score, indicating their severity.
| CVE ID | CVSS Score | Credit |
| CVE-2024-46908 | 8.8 | Sina Kheirkhah (@SinSinology) of Summoning Team |
| CVE-2024-46907 | 8.8 | Sina Kheirkhah (@SinSinology) of Summoning Team |
| CVE-2024-46906 | 8.8 | Sina Kheirkhah (@SinSinology) of Summoning Team |
| CVE-2024-46905 | 8.8 | Sina Kheirkhah (@SinSinology) of Summoning Team |
| CVE-2024-46909 | 9.8 | Andy Niu of Trend Micro |
| CVE-2024-8785 | 9.8 | Tenable |
WhatsUp Gold has released version 24.0.1 on September 20, 2024, which addresses these vulnerabilities.
Customers are strongly advised to download and install this latest version as soon as possible to protect their networks from potential breaches.
The company has provided detailed instructions on performing the upgrade and offers support through its professional services team for any assistance.
Security experts emphasize the importance of keeping software up-to-date to mitigate risks associated with such vulnerabilities.
These types of vulnerabilities can have serious implications if not addressed promptly,” said a cybersecurity analyst at Trend Micro.
Organizations should prioritize upgrading their systems and ensure robust security measures are in place.
WhatsUp Gold has reiterated its commitment to customer security by leveraging development practices to minimize product vulnerabilities and promptly notify users of potential risks.
Analyse AnySuspicious Links Using ANY.RUN's New Safe Browsing Tool: Try It for Free
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…