TCP: Progress WhatsUp Gold WriteDataFile Directory Traversal
This signature detects attempts to exploit a known vulnerability against Progress WhatsUp Gold WriteDataFile. A successful attack can lead to directory traversal and arbitrary code execution.
Extended Description
In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.
Affected Products
Progress whatsup_gold
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vsrx-19.2
srx-19.3
Progress