# CVE-2024-46909

## Summary

- **CVE ID:** CVE-2024-46909
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-22, CWE-73, CWE-16
- **Published:** Dec 2, 2024
- **Last Modified:** Mar 13, 2026

## Description

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.

## Affected Products

- Progress Software Corporation — WhatsUp Gold (2023.1.0)

## References

- [CNA](https://www.progress.com/network-monitoring)
- [CNA](https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024)
- [CNA](https://docs.progress.com/bundle/whatsupgold-release-notes-24-0/page/WhatsUp-Gold-2024.0-Release-Notes.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 48.95%
- **EPSS Percentile:** 98.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._