Article Details
Scrape Timestamp (UTC): 2024-09-27 15:45:03.036
Source: https://thehackernews.com/2024/09/progress-software-releases-patches-for.html
Original Article Text
Click to Toggle View
Progress Software Releases Patches for 6 Flaws in WhatsUp Gold – Patch Now. Progress Software has released another round of updates to address six security flaws in WhatsUp Gold, including two critical vulnerabilities. The issues, the company said, have been resolved in version 24.0.1 released on September 20, 2024. The company has yet to release any details about what the flaws are other than listing their CVE identifiers - Security researcher Sina Kheirkhah of Summoning Team has been credited with discovering and reporting the first four flaws. Andy Niu of Trend Micro has been acknowledged for CVE-2024-46909, while Tenable has been credited for CVE-2024-8785. It's worth noting that Trend Micro recently reported that threat actors are actively exploiting proof-of-concept (PoC) exploits for other recently disclosed security flaws in WhatsUp Gold to conduct opportunistic attacks. Previously, the Shadowserver Foundation said it had observed exploitation attempts against CVE-2024-4885 (CVSS score: 9.8), another critical bug in WhatsUp Gold that was resolved by Progress in June 2024. WhatsUp Gold Customers are recommended to apply the latest fixes as soon as possible to mitigate potential threats.
Daily Brief Summary
Progress Software has released updates for six security vulnerabilities in WhatsUp Gold, including two labeled as critical.
The latest patches are in version 24.0.1, which became available on September 20, 2024.
Security researchers Sina Kheirkhah and Andy Niu, alongside cybersecurity firm Tenable, identified and reported these vulnerabilities.
Specific details on the nature of the vulnerabilities have not been disclosed, beyond their CVE identifiers.
Trend Micro reported that recent vulnerabilities have been exploited by threat actors using PoC exploits.
There have been previous attacks targeting WhatsUp Gold, specifically a critical bug (CVE-2024-4885) addressed earlier in June 2024.
WhatsUp Gold customers are strongly advised to install the new patches immediately to protect against potential exploitation of these flaws.