Junglewise Threat Intelligence

CVE-2024-1212: Progress Kemp LoadMaster OS Command Injection Vulnerability

CVE-2024-1212 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2024-11-18

Vendors: Progress, Progress Software Corporation.

Executive brief

Progress Kemp LoadMaster contains an OS command injection vulnerability in its management interface. An unauthenticated remote attacker can exploit this to execute arbitrary system commands with high privileges.

Affected products

  • Progress Software Corporation LoadMaster 7.2.48.1 - 7.2.48.10, 7.2.54.0 - 7.2.54.8, 7.2.55.0 - 7.2.59.2

Timeline

  • 2024-02-21: disclosed: Vulnerability received by Progress Software Corporation
  • 2024-11-18: advisory: Initial publication of the advisory
  • 2024-11-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-11-18: exploited: Reported as exploited in the wild per CISA KEV entry