PT-2024-2428 · Kemp · Kemp Loadmaster

Published

2024-02-21

·

Updated

2026-05-02

·

CVE-2024-1212

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Progress Kemp LoadMaster (affected versions not specified)
Description Unauthenticated remote attackers can access the system through the management interface to execute arbitrary system commands. This issue occurs because the software fails to neutralize special elements used in operating system commands. Successful exploitation can allow an attacker to escalate privileges to root, granting full control of the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-02383
CVE-2024-1212

Affected Products

Kemp Loadmaster