Progress Kemp LoadMaster
cpe:2.3:a:kemptechnologies:load_master:*:*:*:*:*:*:*, +1 more
- <= 7.2.62.2
A remote code execution vulnerability has been identified in the Progress LoadMaster API. This issue arises from improper input sanitization in the 'killsession' command, allowing authenticated attackers with 'All' permissions to execute arbitrary commands on the LoadMaster appliance. The vulnerability affects Progress LoadMaster GA versions through 7.2.62.2 and LTSF versions through 7.2.54.16.
Exploitation of this vulnerability allows authenticated attackers to execute arbitrary commands on the LoadMaster appliance.
Progress LoadMaster has released a patch for this vulnerability in version 7.2.63.1 for the GA channel and 7.2.54.17 for the LTSF channel. Instructions for upgrading are available on the Progress Community LoadMaster Download Hub.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.