ZeroHour
Security Affairspublished ()ingested @securityaffairs

Progress Software fixed multiple high

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-1212
Unauthenticated OS Command Injection RCE in Progress Kemp LoadMaster

CVE-2024-1212 is a critical (CVSS 9.8) unauthenticated OS command injection flaw (CWE-78) in the management interface of Progress Kemp LoadMaster, a load balancer / application delivery appliance. A remote attacker with no credentials can send crafted requests to the management interface, causing the appliance to execute arbitrary operating system commands; security reporting indicates commands can be run with root privileges. Successful exploitation gives attackers full control of the appliance and potential access to the backend servers and traffic it manages. Any organization running an affected Kemp LoadMaster appliance or virtual appliance whose management interface is reachable is exposed. Exploitation is occurring in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-18, carries a 95.4% EPSS probability of exploitation within 30 days, and recent headlines report active exploitation attempts.

Do: Apply the vendor-supplied update immediately per Progress's advisory (the CISA KEV required action is to apply vendor mitigations or discontinue use of the product), since no public PoC is needed for attackers to exploit it. Until patched, restrict the LoadMaster management interface (web UI and API) to trusted management networks behind a firewall or VPN, and review appliance logs for signs of unauthenticated access or unexpected command execution. Treat any suspected compromise as high risk, as ransomware use is currently unknown.

9.895% KEV
  • Progress Kemp LoadMaster
largetens of thousands of internet-exposed LoadMaster appliances
CVE-2024-56132
+4 in the same advisory: …56131 …56133 …56134 …56135
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows :

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1 (inclusive)

NVD description · AI analysis pending
6.86%
  • progress multi-tenant loadmaster
  • progress loadmaster

Indicators of compromiseAll →

TypeIndicatorContext
ipv47.1.35.12s Upgrade to LTSF or GA 5 Feb 2025 Multi-Tenant LoadMaster 7.1.35.12 and all prior versions 7.1.35.13 (GA) XML validation file
ipv47.1.35.135 Multi-Tenant LoadMaster 7.1.35.12 and all prior versions 7.1.35.13 (GA) XML validation file 5 Feb 2025 The company is not awar
ipv47.2.48.12inclusive) 7.2.54.13 (LTSF) XML validation file 5 Feb 2025 7.2.48.12 and all prior versions Upgrade to LTSF or GA 5 Feb 2025 Mu
ipv47.2.54.122.61.0 (GA) XML validation file 5 Feb 2025 From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.54.13 (LTSF) XML validation file 5 Feb 202
ipv47.2.54.13ion file 5 Feb 2025 From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.54.13 (LTSF) XML validation file 5 Feb 2025 7.2.48.12 and all pri
ipv47.2.60.1Patched Versions Release Date LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) 7.2.61.0 (GA) XML validation file 5 Feb 2025 F
Full article409 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 11, 2025

Progress Software fixed multiple vulnerabilities in its LoadMaster software, which could be exploited to execute arbitrary system commands.

Progress Software has addressed multiple high-severity security vulnerabilities (CVE-2024-56131, CVE-2024-56132, CVE-2024-56133, CVE-2024-56134, CVE-2024-56135) in its LoadMaster software.

Progress Software’s LoadMaster is a high-performance load balancer and application delivery controller (ADC) designed to optimize the availability, security, and performance of web applications and services. It helps distribute network traffic efficiently across multiple servers to ensure reliability and scalability.

Below are the descriptions of these vulnerabilities:

  • CVE-2024-56131 (CVSS scores: 8.4) is an Improper input validation vulnerability that could allow an authenticated User in LoadMaster to achieve OS Command Injection.
  • CVE-2024-56132 (CVSS scores: 8.4) is an Improper input validation vulnerability that could allow an authenticated User in LoadMaster to achieve OS Command Injection.
  • CVE-2024-56133 is an Improper input validation vulnerability that could allow an authenticated User in LoadMaster to achieve OS Command Injection.
  • CVE-2024-56135 (CVSS scores: 8.4) is an Improper input validation vulnerability that could allow an authenticated User in LoadMaster to achieve OS Command Injection.

Once a remote attacker gained access to the management interface of LoadMaster and successfully authenticated could execute arbitrary system commands by using specially crafted HTTP requests.

The last high-severity flaw addressed by Progress, tracked as CVE-2024-56134 (CVSS score: 8.4), is an improper input validation vulnerability that could allow remote attackers who gain access to the management interface and successfully authenticate to download the content of any file on the system. The attacker could exploit the flaw via a specially crafted HTTP request

The vulnerabilities impact the following versions: 

 Product Affected Versions Patched Versions Release Date 
LoadMaster  From 7.2.55.0 to 7.2.60.1 (inclusive)  7.2.61.0 (GA) 
XML validation file 
5 Feb 2025 
   From 7.2.49.0 to 7.2.54.12 (inclusive)  7.2.54.13 (LTSF) 
XML validation file 
5 Feb 2025 
   7.2.48.12 and all prior versions  Upgrade to  
LTSF or GA 
5 Feb 2025 
Multi-Tenant LoadMaster7.1.35.12 and all prior versions  7.1.35.13 (GA) 
XML validation file 
5 Feb 2025

The company is not aware of attacks in the wild exploiting one of the above vulnerabilities.

In November, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the CVE-2024-1212 Progress Kemp LoadMaster issue to its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2024-1212 is a Progress Kemp LoadMaster OS command injection issue that unauthenticated remote attackers can exploit to execute arbitrary system commands, posing significant security risks.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Progress LoadMaster)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/174103/security/progress-software-loadmaster-software-flaws.html