CVE-2024-4883: Progress WhatsUp Gold

Critical severity, CVSS 9.8. EPSS: 64.5% chance of exploitation in the next 30 days.

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.

Affected products

  • Progress WhatsUp Gold: before 23.1.3 (fixed in 23.1.3)

Published 2024-06-25. Last modified 2026-06-17.