HTTP: Progress WhatsUp Gold SnmpExtendedActiveMonitor Directory Traversal

This signature detects attempts to exploit a known vulnerability against Progress WhatsUp Gold. A successful attack can lead to directory traversal and arbitrary code execution.

Extended Description

In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use aspecially crafted HTTP request that can lead to information disclosure.

Affected Products

Progress whatsup_gold

Short Name
HTTP:DIR:PRESS-SNMPEXT-DIR-TRSL
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2024-12105 Directory Gold Progress SnmpExtendedActiveMonitor Traversal WhatsUp
Release Date
01/21/2025
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3775
False Positive
Unknown
Vendors

Progress

Found a potential security threat?