Progress WhatsUp Gold contained four vulnerabilities that could be chained from unauthenticated access to disclosure of application users’ plaintext passwords, arbitrary local-file reads, and capture of the server’s Net-NTLMv2 hash. The chain used CVE-2022-29847, a blind SSRF in report rendering that transmitted usernames and encrypted passwords to an attacker-controlled host, together with CVE-2022-29846, which exposed the pre-authentication product serial number used as the credential-encryption salt.
An attacker could use the exposed serial number to decrypt captured credentials, authenticate to the application, and exploit CVE-2022-29845 directory traversal to read local files or trigger outbound SMB authentication. The authenticated CVE-2022-29848 WebContent SSRF could also leak the Windows host’s Net-NTLMv2 hash. Progress received the vulnerability report on April 11, 2022, provided a patched build on April 28, and researchers confirmed remediation of all four flaws on May 11.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The researchers confirmed that Progress had fixed all four reported WhatsUp Gold vulnerabilities.
Progress provided the researchers with a patched WhatsUp Gold version for validation of the reported vulnerabilities.
Researchers disclosed four vulnerabilities in Progress WhatsUp Gold, including pre-authentication SSRF and serial-number exposure plus authenticated local-file disclosure and SSRF, which could be chained to recover credentials, read local files, and capture Net-NTLMv2 hashes.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.