Progress Kemp LoadMaster
cpe:2.3:a:kemptechnologies:load_master:*:*:*:*:*:*:*
- <= 7.2.62.2
- <= 7.2.54.16
A remote code execution vulnerability has been identified in Progress LoadMaster versions through v7.2.62.2 and LTSF v7.2.54.16. This vulnerability allows authenticated attackers with 'All' permissions to execute arbitrary commands on the LoadMaster appliance. The issue arises from unsanitized input in custom Web Application Firewall (WAF) rule files during the file upload process, which can be exploited to inject and execute commands on the server.
Exploitation of this vulnerability allows for arbitrary command execution on the affected LoadMaster appliance.
Progress LoadMaster has released a patch for this vulnerability in version v7.2.63.1 for the GA channel and v7.2.54.17 for the LTSF channel. Instructions for upgrading can be found on the Progress Community LoadMaster Download Hub.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.