Fiche vulnérabilité
CVE-2022-42711 : faille critique progress whatsup gold (CVSS 9.6)
Description
In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.
En bref
- Sévérité
- Critique (CVSS 9.6)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 12 oct. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- progress whatsup gold