Progress LoadMaster
cpe:2.3:a:progress:loadmaster:*:*:*:*:*:*:*
- >= 7.2.55.0, <= 7.2.60.1
- >= 7.2.49.0, <= 7.2.54.12
- ~7.2.48.12
A vulnerability allowing OS command injection has been identified in Progress LoadMaster. This issue affects authenticated users and is present in LoadMaster versions 7.2.55.0 through 7.2.60.1 (inclusive), 7.2.49.0 through 7.2.54.12 (inclusive), 7.2.48.12, and all prior versions. The vulnerability arises from improper input validation, allowing authenticated users to execute arbitrary system commands by sending crafted HTTP requests through the management interface.
Exploitation of this vulnerability allows authenticated users to execute arbitrary system commands on the LoadMaster appliance.
To address this vulnerability, users should upgrade to LoadMaster version 7.2.61.0 (GA), 7.2.54.13 (LTSF), or for Multi-Tenant LoadMaster, 7.1.35.13 (GA). Instructions for upgrading LoadMaster firmware are available in the LoadMaster Upgrade Firmware Knowledge Base article.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.