Where
-Infinity
0
Command Injection, OS Command Injection
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution.

1 / 2
Source: CISA
First published (updated )
Severity
9.8
Command Injection, OS Command Injection
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

1 / 2
Source: NVD
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).

First published (updated )
Severity
8.4
OS Command Injection, Command Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

First published (updated )
Severity
8.4
OS Command Injection, Command Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

First published (updated )
Severity
8.4
Command Injection, OS Command Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command

First published (updated )
Severity
8.4
Command Injection, OS Command Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.

First published (updated )
Severity
8.4
Command Injection, OS Command Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command

First published (updated )
Severity
8.4
Command Injection, OS Command Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command

First published (updated )
Severity
8.4
OS Command Injection, Command Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.

First published (updated )
Severity
8.4
OS Command Injection, Command Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.

First published (updated )
Severity
8.4
OS Command Injection, Command Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.

First published (updated )
Severity
8
AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.

First published (updated )
Severity
8
AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203