Umbra Wiki cve cve/CVE-2024-1212
Back to wiki

CVE-2024-1212 — Progress Kemp LoadMaster OS Command Injection Vulnerability

provenance: imported · CVE: CVE-2024-1212

CVE-2024-1212: Progress Kemp LoadMaster OS Command Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Progress
Product Kemp LoadMaster
Date added 2024-11-18
Due date 2024-12-09
Ransomware campaign use Unknown

Description

Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Required action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Notes

https://community.progress.com/s/article/Release-Notice-LMOS-7-2-59-2-7-2-54-8-7-2-48-10-CVE-2024-1212 ; https://nvd.nist.gov/vuln/detail/CVE-2024-1212

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-1212
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog