Exploited Known exploited (KEV) Ransomware use CVE-2024-6670

Progress WhatsUp Gold SQL injection (CVE-2024-6670) — carrying the condition that the application is configured with only a single user

Progress WhatsUp Gold Added to KEV Sep 16, 2024 Federal remediation due 2024-10-07

A SQL injection vulnerability in network monitoring software. An unauthenticated attacker is described as able to retrieve a user encrypted password, but only where the application is configured with a single user.

Key facts

  • CVE IDCVE-2024-6670
  • Affected (vendor / product)Progress WhatsUp Gold
  • CWECWE-89
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2024-10-07 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • The affected product is Progress WhatsUp Gold, classified as SQL injection.
  • An unauthenticated attacker is described as able to retrieve a user encrypted password.
  • The description states the condition that the application is configured with only a single user.
  • A stated condition helps in judging priority, but checking presumes knowing your own configuration.
  • Monitoring must connect across everything it monitors, and that breadth becomes the breadth of any effect.

1When a condition is stated

Most catalog descriptions do not spell out conditions. This one exceptionally records that it applies where the application is configured with only a single user. That wording carries two implications.

Where a condition is statedWhere none is stated
You can check whether it applies to youIt must be treated as broadly applicable
Priority may be lowered if it does notThere is less to judge priority on
Checking itself takes effortNo checking is needed, but action is required regardless

A stated condition means priority can be judged by checking. Checking, though, presumes knowing your own configuration. The record of a condition helps only where that is known.

2The class of flaw

  1. 1The mechanismA program assembles a statement to query a database
  2. 2Where the issue liesHow a string received from outside is placed into that statement
  3. 3Where the flaw existsCharacters in the string are read as part of the query
  4. 4The result hereA user encrypted password may be retrieved

This site covers several classes where a string from outside lands somewhere read as instruction. SQL injection is the one where a database query is the target.

3An encrypted password

The description says what may be retrieved is an encrypted password — not usable as it stands. It matters nonetheless because the fact of its being held, and the form in which it is held, leaving the system can become material for a next step. This site covers another case where hashed passwords could be read out, and the point is shared.

4Where monitoring sits

What this affectsNetwork monitoring softwareIt must connect across everything it monitors
Entries this site holds as of 2026-09-041,694, with 100 published articles330 unpublished entries carry known ransomware use
Due date here21 daysAdded September 16, 2024, due October 7

Monitoring cannot do its job without connecting across everything it monitors. This site covers the same shape for support tooling and for backup systems, and the pattern recurs across differences in placement: breadth of connection required by a role becomes breadth of effect.

Why it matters

Entries stating conditions allow priority to be judged, but judging requires knowing your own configuration. Monitoring, support and backup systems all connect across everything by role, so their effects spread alike despite differing placement.

FAQ

If the condition does not apply, is action unnecessary?
A stated condition helps judge priority, but confirming whether it applies presumes knowing your own configuration, so checking against vendor guidance comes first.
Is an encrypted password still a problem?
It is not usable as it stands, but the fact of its being held and the form it takes leaving the system can become material for a next step.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Security#CISA#KEV#Network monitoring#SQL injection
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.