ZeroHour

CVE-2024-1212

KEVlarge

Unauthenticated OS Command Injection RCE in Progress Kemp LoadMaster

CISA: Progress Kemp LoadMaster OS Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
95%p100
Published
()
KEV added
AI analysis

CVE-2024-1212 is a critical (CVSS 9.8) unauthenticated OS command injection flaw (CWE-78) in the management interface of Progress Kemp LoadMaster, a load balancer / application delivery appliance. A remote attacker with no credentials can send crafted requests to the management interface, causing the appliance to execute arbitrary operating system commands; security reporting indicates commands can be run with root privileges. Successful exploitation gives attackers full control of the appliance and potential access to the backend servers and traffic it manages. Any organization running an affected Kemp LoadMaster appliance or virtual appliance whose management interface is reachable is exposed. Exploitation is occurring in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-18, carries a 95.4% EPSS probability of exploitation within 30 days, and recent headlines report active exploitation attempts.

What to do: Apply the vendor-supplied update immediately per Progress's advisory (the CISA KEV required action is to apply vendor mitigations or discontinue use of the product), since no public PoC is needed for attackers to exploit it. Until patched, restrict the LoadMaster management interface (web UI and API) to trusted management networks behind a firewall or VPN, and review appliance logs for signs of unauthenticated access or unexpected command execution. Treat any suspected compromise as high risk, as ransomware use is currently unknown.

Affected
Progress Kemp LoadMaster
Estimated exposure
largetens of thousands of internet-exposed LoadMaster appliances — Public internet-wide scans (e.g., Censys/Shodan) have shown on the order of tens of thousands of Kemp LoadMaster devices with exposed management/WUI interfaces, and LoadMaster is widely deployed as an edge load balancer whose admin…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

CISA Known Exploited Vulnerability
Affected
Progress Kemp LoadMaster
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
progress
Products
loadmaster
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news