We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-1212

LoadMaster Pre-Authenticated OS Command Injection



AssignerProgressSoftware
Reserved2024-02-02
Published2024-02-21
Updated2024-11-19

Description

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.



CRITICAL: 10.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA Known Exploited Vulnerability

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Product status

Default status
affected

7.2.48.1 before 7.2.48.10
affected

7.2.54.0 before 7.2.54.8
affected

7.2.55.0 before 7.2.59.2
affected

Credits

Rhino Security Labs finder

References

https://kemptechnologies.com/ product

https://freeloadbalancer.com/ product

https://support.kemptechnologies.com/hc/en-us/articles/24325072850573-Release-Notice-LMOS-7-2-59-2-7-2-54-8-7-2-48-10-CVE-2024-1212 vendor-advisory

https://support.kemptechnologies.com/hc/en-us/articles/23878931058445-LoadMaster-Security-Vulnerability-CVE-2024-1212 vendor-advisory

cve.org CVE-2024-1212

nvd.nist.gov CVE-2024-1212

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-1212
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.