CVE-2022-29847
Summary
| CVE | CVE-2022-29847 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-11 18:15:00 UTC |
| Updated | 2022-05-20 14:36:00 UTC |
| Description | In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host. |
Risk And Classification
Problem Types: CWE-918
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ipswitch | Whatsup Gold | 22.0.0 | All | All | All |
| Application | Ipswitch | Whatsup Gold | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WhatsUp Gold Network Monitoring Software | Progress | MISC | www.progress.com | |
| Progress Customer Community | MISC | community.progress.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.