Progress Kemp LoadMaster
cpe:2.3:a:kemptechnologies:load_master:*:*:*:*:*:*:*
- <= 7.2.62.2
- <= 7.2.54.16
A remote code execution vulnerability has been identified in the Progress LoadMaster API. This issue arises from improper input sanitization in the 'aclcontrol' command, allowing authenticated attackers with 'VS Administration' permissions to execute arbitrary commands on the LoadMaster appliance. The vulnerability affects Progress LoadMaster GA versions through 7.2.62.2 and LTSF versions through 7.2.54.16.
Exploitation of this vulnerability allows for arbitrary command execution on the affected LoadMaster appliance.
Users are advised to upgrade to Progress LoadMaster v7.2.63.1 or Progress LoadMaster LTSF v7.2.54.17. Instructions for upgrading can be found on the Progress Community LoadMaster Download Hub.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.