PT-2024-38438 · Progress · Loadmaster+2
Marius Walter
·
Published
2024-09-05
·
Updated
2025-07-02
·
CVE-2024-7591
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LoadMaster versions 7.2.40.0 and above
ECS versions (all versions)
Multi-Tenancy versions 7.1.35.4 and above
Description
The issue is related to an improper input validation vulnerability in Progress LoadMaster, allowing OS Command Injection. This vulnerability enables potential malicious actors to execute commands on the underlying operating system without authentication. The vulnerability is critical and has been described as an improper input validation bug that results in OS command injection. Unauthenticated, remote attackers can execute system commands.
Recommendations
For LoadMaster versions 7.2.40.0 and above: Apply the emergency patch released by Progress Software to fix the vulnerability.
For ECS versions (all versions): Apply the security updates released by Progress Software to fix the vulnerability.
For Multi-Tenancy versions 7.1.35.4 and above: Apply the security updates released by Progress Software to fix the vulnerability.
As a temporary workaround, consider restricting access to the management interface of LoadMaster to minimize the risk of exploitation.
Fix
LPE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecs
Loadmaster
Multi-Tenancy