APP: Progress WhatsUp Gold OnMessage Insecure Deserialization
This signature detects attempts to exploit a known vulnerability against Progress WhatsUp Gold Distributed Edition. A successful attack can lead to arbitrary code execution.
Extended Description
In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserializationtool to achieve a Remote Code Execution as SYSTEM. The vulnerability exists in the main message processing routinesNmDistributed.DistributedServiceBehavior.OnMessage for server and NmDistributed.DistributedClient.OnMessage for clients.
Affected Products
Progress whatsup_gold
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vsrx-19.2
srx-19.3
Progress