First published: Wed Feb 21 2024(Updated: )
Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution.
Credit: security@progress.com security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Kemp LoadMaster | >=7.2.48.1<7.2.48.10 | |
Progress Kemp LoadMaster | >=7.2.54.0<7.2.54.8 | |
Progress Kemp LoadMaster | >=7.2.55.0<7.2.59.2 | |
Kemp LoadMaster |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-1212 is classified as a high severity vulnerability due to its capability of allowing unauthenticated remote code execution.
To fix CVE-2024-1212, update your Progress Kemp LoadMaster to the latest patched version provided by Progress.
CVE-2024-1212 affects Progress Kemp LoadMaster versions between 7.2.48.1 and 7.2.48.10, as well as specific versions up to 7.2.59.2.
Yes, CVE-2024-1212 can be exploited remotely by an unauthenticated attacker via the LoadMaster management interface.
Due to CVE-2024-1212, an attacker can execute arbitrary system commands on the affected system.