ZDI-CAN-27593: ZDI-26-052: Progress Software Kemp LoadMaster getcipherset Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2025-13444.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27593?
ZDI-CAN-27593 has been rated as a critical severity vulnerability due to its potential for remote code execution.
How do I fix ZDI-CAN-27593?
To fix ZDI-CAN-27593, apply the latest security updates provided by Progress Software for Kemp LoadMaster.
What type of vulnerability is ZDI-CAN-27593?
ZDI-CAN-27593 is classified as a command injection vulnerability allowing remote code execution.
Who can exploit ZDI-CAN-27593?
ZDI-CAN-27593 can be exploited by network-adjacent attackers with valid authentication.
What software is affected by ZDI-CAN-27593?
ZDI-CAN-27593 affects installations of Progress Software Kemp LoadMaster.