EXPOSURES › CVE-2024-6670
CVE-2024-6670
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated SQL injection in Progress WhatsUp Gold lets attackers steal encrypted passwords when only one user is configured.
The SQL injection flaw allows unauthenticated attackers to extract encrypted user passwords if the system is set up with a single user, exposing credentials and enabling further compromise. DIB organizations must patch this immediately and audit single-user configurations to prevent credential theft and potential ransomware entry. This is an actively exploited vulnerability linked to ransomware campaigns.
Shame score — A critical SQL injection flaw actively exploited in the wild to steal credentials, compounded by the lack of authentication barriers and the known risk of single-user configurations.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user.