Executive brief
Progress Kemp LoadMaster contains an OS command injection vulnerability in its management interface. An unauthenticated remote attacker can exploit this to execute arbitrary system commands with high privileges.
Affected products
- Progress Software Corporation LoadMaster 7.2.48.1 - 7.2.48.10, 7.2.54.0 - 7.2.54.8, 7.2.55.0 - 7.2.59.2
Timeline
- 2024-02-21: disclosed: Vulnerability received by Progress Software Corporation
- 2024-11-18: advisory: Initial publication of the advisory
- 2024-11-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-11-18: exploited: Reported as exploited in the wild per CISA KEV entry