{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-22T18:12:43.140","vulnerabilities":[{"cve":{"id":"CVE-2024-5014","sourceIdentifier":"security@progress.com","published":"2024-06-25T21:16:00.703","lastModified":"2026-06-17T08:14:54.507","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature. This allows any authenticated user to retrieve ASP reports from an HTML form."},{"lang":"es","value":"En las versiones de WhatsUp Gold lanzadas antes de 2023.1.3, existe una vulnerabilidad de Server Side Request Forgery en la función GetASPReport. Esto permite que cualquier usuario autenticado recupere informes ASP desde un formulario HTML."}],"affected":[{"source":"security@progress.com","affectedData":[{"vendor":"Progress Software Corporation","product":"WhatsUp Gold","defaultStatus":"affected","modules":["API Endpoint"],"platforms":["Windows"],"versions":[{"version":"2023.1.0","lessThan":"2023.1.3","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"progress","product":"whatsup_gold","defaultStatus":"affected","cpes":["cpe:2.3:a:progress:whatsup_gold:2023.1.0:*:*:*:*:*:*:*"],"versions":[{"version":"2023.1.0","lessThan":"2023.1.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@progress.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-26T14:08:01.097607Z","id":"CVE-2024-5014","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@progress.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:*","versionEndExcluding":"23.1.3","matchCriteriaId":"C22487E3-6723-40C7-86A0-764EBAA37A55"}]}]}],"references":[{"url":"https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024","source":"security@progress.com","tags":["Vendor Advisory"]},{"url":"https://www.progress.com/network-monitoring","source":"security@progress.com","tags":["Product"]},{"url":"https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.progress.com/network-monitoring","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]}]}}]}