PT-2018-18848 · Kemp · Kemp Loadmaster Operating System

Published

2018-05-25

·

Updated

2019-10-03

·

CVE-2018-9091

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KEMP LoadMaster Operating System (LMOS) versions 6.0.44 through 7.2.41.2 KEMP LoadMaster Operating System (LMOS) Long Term Support (LTS) versions prior to 7.1.35.5
Description A critical issue related to Session Management could allow an unauthenticated, remote attacker to bypass security protections, gain system privileges, and execute elevated commands such as ls, ps, cat, etc., thereby compromising the system. This could potentially lead to the exposure of sensitive system data, including certificates, private keys, and other information.
Recommendations For KEMP LoadMaster Operating System (LMOS) versions 6.0.44 through 7.2.41.2, update to a version after 7.2.41.2 to resolve the issue. For KEMP LoadMaster Operating System (LMOS) Long Term Support (LTS) versions prior to 7.1.35.5, update to version 7.1.35.5 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-9091

Affected Products

Kemp Loadmaster Operating System