CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2024-1212

CVSS 10.0v3.1pub. 2024-02-21upd. 2026-07-13

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

🤖 AI Analysis
How it works

An attacker gains access to the system through the LoadMaster management interface without requiring any credentials. The vulnerability is classified as command injection (CWE-78), meaning that input data supplied by the attacker is passed directly to the system shell without proper validation or sanitization. This allows execution of arbitrary commands with the privileges of the process handling the management interface.

Impact

An unauthenticated attacker can take full control of the device by executing arbitrary system commands — which includes data theft, configuration modification, backdoor installation, and potential lateral movement within the internal network.

Mitigation & patch

LoadMaster software must be updated immediately to version LMOS 7.2.59.2, 7.2.54.8, or 7.2.48.10 (depending on the branch in use). Additionally, it is recommended to restrict access to the management interface only to trusted IP addresses and to isolate the management interface from the production network.

Who is affected

Progress LoadMaster — versions indicated in the manufacturer's references (patch available in LMOS 7.2.59.2, 7.2.54.8, and 7.2.48.10 versions according to the manufacturer's documentation)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Progress Loadmaster

    OS
    Progress
    7.2.48.1 – 7.2.48.10 (excl.)7.2.54.0 – 7.2.54.8 (excl.)7.2.55.0 – 7.2.59.2 (excl.)

CISA KEV — detailsi

Vendori
Progress
Producti
Kemp LoadMaster
Added to KEVi
November 18, 2024
Remediation deadline (US Federal)i
December 9, 2024(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 9 grudnia 2024
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2026-8037CRITICAL9.6⚠ KEVPL ✓same product

RCE przez command injection w API urządzeń Progress ADC (LoadMaster)

CVE-2026-59689HIGH8.0PL ✓same product

Privilege escalation do root w produktach Progress Software (LoadMaster, ECS, MOVEit WAF)

CVE-2026-59686HIGH8.4PL ✓same product

OS Command Injection w produktach Progress Software — zarządzanie przez interfejs admina

CVE-2026-59687HIGH8.4PL ✓same product

Command Injection w Progress LoadMaster i powiązanych produktach via Geo Location

CVE-2026-59688HIGH8.4PL ✓same product

Command Injection w Progress LoadMaster i MOVEit WAF — funkcja przywracania kopii zapasowej