PT-2025-11649 · Kemp · Kemp Loadmaster
Published
2025-03-10
·
Updated
2025-06-26
·
CVE-2025-1758
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Progress LoadMaster versions 7.2.40.0 and above
ECS versions (all versions)
Multi-Tenancy versions 7.1.35.4 and above
Description
The issue is related to an improper input validation vulnerability in Progress LoadMaster, which allows a buffer overflow. This can lead to remote code execution on affected systems. The vulnerability affects Progress LoadMaster, ECS, and Multi-Tenancy products.
Recommendations
For LoadMaster versions 7.2.40.0 and above, update to a version that includes the fix for this issue.
For ECS, since all versions are affected, apply the recommended patch or configuration changes as soon as they become available.
For Multi-Tenancy versions 7.1.35.4 and above, consider disabling the vulnerable component or restricting access to it until a patch is available.
As a temporary workaround, consider restricting access to the vulnerable API endpoints or functions until a patch is available.
Fix
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kemp Loadmaster