PT-2018-18848 · Kemp · Kemp Loadmaster Operating System
Published
2018-05-25
·
Updated
2019-10-03
·
CVE-2018-9091
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
KEMP LoadMaster Operating System (LMOS) versions 6.0.44 through 7.2.41.2
KEMP LoadMaster Operating System (LMOS) Long Term Support (LTS) versions prior to 7.1.35.5
Description
A critical issue related to Session Management could allow an unauthenticated, remote attacker to bypass security protections, gain system privileges, and execute elevated commands such as
ls, ps, cat, etc., thereby compromising the system. This could potentially lead to the exposure of sensitive system data, including certificates, private keys, and other information.Recommendations
For KEMP LoadMaster Operating System (LMOS) versions 6.0.44 through 7.2.41.2, update to a version after 7.2.41.2 to resolve the issue.
For KEMP LoadMaster Operating System (LMOS) Long Term Support (LTS) versions prior to 7.1.35.5, update to version 7.1.35.5 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kemp Loadmaster Operating System