Description
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Progress / LoadMaster7.2.48.1 – 7.2.48.10
- Progress Software / LoadMaster7.2.48.1 – 7.2.48.10
- Progress Software / LoadMaster7.2.54.0 – 7.2.54.8
- Progress Software / LoadMaster7.2.55.0 – 7.2.59.2
Exploits & proofs of concept
- nucleiProgress Kemp LoadMaster - Command Injectionby DhiyaneshDK
References
- MISChttps://kemptechnologies.com/
- MISChttps://freeloadbalancer.com/
- MISChttps://support.kemptechnologies.com/hc/en-us/articles/24325072850573-Release-Notice-LMOS-7-2-59-2-7-2-54-8-7-2-48-10-CVE-2024-1212
- MISChttps://support.kemptechnologies.com/hc/en-us/articles/23878931058445-LoadMaster-Security-Vulnerability-CVE-2024-1212
Updated 42m ago · 8 sources