target entity

Progress

8 source-linked records in the current knowledge graph.

high

CVE-2024-4885: Progress WhatsUp Gold Path Traversal Vulnerability

Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-4885EPSS 99.3%ProgressWhatsUp Gold
CISA KEV ↗ · unattributed attribution
high

CVE-2024-1212: Progress Kemp LoadMaster OS Command Injection Vulnerability

Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-1212EPSS 95.4%Kemp LoadMasterProgress
CISA KEV ↗ · unattributed attribution
high

CVE-2024-6670: Progress WhatsUp Gold SQL Injection Vulnerability

Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-6670EPSS 94.7%ProgressWhatsUp Gold
CISA KEV ↗ · unattributed attribution
high

CVE-2023-40044: Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-40044EPSS 90.1%ProgressWS_FTP Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-34362: Progress MOVEit Transfer SQL Injection Vulnerability

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements. Required action: Apply updates per vendor instructions.

CVE-2023-34362EPSS 99.9%MOVEit TransferProgress
CISA KEV ↗ · unattributed attribution
high

CVE-2017-9248: Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability

Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files. Required action: Apply updates per vendor instructions.

CVE-2017-9248EPSS 75.1%ASP.NET AJAX and SitefinityProgress
CISA KEV ↗ · unattributed attribution · 3 IOCs