HTTP: Progress WhatsUp Gold CommunityController Unrestricted File Upload

This signature detects attempts to exploit a known vulnerability against Progress. A successful attack can lead to arbitrary code execution.

Extended Description

In WhatsUp Gold versions released before 2023.1.3,an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileges.

Affected Products

Progress whatsup_gold

Short Name
HTTP:CTS:PROGRESS-GL-FL-UPLOAD
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2024-4884 CommunityController File Gold Progress Unrestricted Upload WhatsUp
Release Date
07/31/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3739
False Positive
Unknown
Vendors

Progress

Found a potential security threat?