CVE-2024-1212
KEVlargeUnauthenticated OS Command Injection RCE in Progress Kemp LoadMaster
CISA: Progress Kemp LoadMaster OS Command Injection Vulnerability
CVE-2024-1212 is a critical (CVSS 9.8) unauthenticated OS command injection flaw (CWE-78) in the management interface of Progress Kemp LoadMaster, a load balancer / application delivery appliance. A remote attacker with no credentials can send crafted requests to the management interface, causing the appliance to execute arbitrary operating system commands; security reporting indicates commands can be run with root privileges. Successful exploitation gives attackers full control of the appliance and potential access to the backend servers and traffic it manages. Any organization running an affected Kemp LoadMaster appliance or virtual appliance whose management interface is reachable is exposed. Exploitation is occurring in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-18, carries a 95.4% EPSS probability of exploitation within 30 days, and recent headlines report active exploitation attempts.
What to do: Apply the vendor-supplied update immediately per Progress's advisory (the CISA KEV required action is to apply vendor mitigations or discontinue use of the product), since no public PoC is needed for attackers to exploit it. Until patched, restrict the LoadMaster management interface (web UI and API) to trusted management networks behind a firewall or VPN, and review appliance logs for signs of unauthenticated access or unexpected command execution. Treat any suspected compromise as high risk, as ransomware use is currently unknown.
| Progress Kemp LoadMaster | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
- Affected
- Progress Kemp LoadMaster
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- progress
- Products
- loadmaster
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H