An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HProgress Connection Manager For Objectscale
APPProgress< 7.2.63.3Progress Ecs Connection Manager
APPProgress< 7.2.63.3Progress Loadmaster
OSProgress< 7.2.54.197.2.55.0 – 7.2.63.3 (excl.)Progress Moveit Web Application Firewall
APPProgress< 7.2.63.3
Related vulnerabilities
RCE przez command injection w API urządzeń Progress ADC (LoadMaster)
Progress LoadMaster – nieuwierzytelnione RCE przez command injection w interfejsie zarządzania
Privilege escalation do root w produktach Progress Software (LoadMaster, ECS, MOVEit WAF)
OS Command Injection w produktach Progress Software — zarządzanie przez interfejs admina
Command Injection w Progress LoadMaster i MOVEit WAF — funkcja przywracania kopii zapasowej