CVE-2024-1212: Progress Kemp LoadMaster OS Command Injection Vulnerability
Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution.
Other sources
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
— NVD
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-1212?
CVE-2024-1212 is classified as a high severity vulnerability due to its capability of allowing unauthenticated remote code execution.
How do I fix CVE-2024-1212?
To fix CVE-2024-1212, update your Progress Kemp LoadMaster to the latest patched version provided by Progress.
Which versions of Progress Kemp LoadMaster are affected by CVE-2024-1212?
CVE-2024-1212 affects Progress Kemp LoadMaster versions between 7.2.48.1 and 7.2.48.10, as well as specific versions up to 7.2.59.2.
Can CVE-2024-1212 be exploited remotely?
Yes, CVE-2024-1212 can be exploited remotely by an unauthenticated attacker via the LoadMaster management interface.
What types of attacks can occur due to CVE-2024-1212?
Due to CVE-2024-1212, an attacker can execute arbitrary system commands on the affected system.