EXPOSURES › CVE-2024-1212
CVE-2024-1212
HIGH ⌖ ON CISA KEV · EXPLOITEDProgress Kemp LoadMaster OS command injection allows unauthenticated remote attackers to execute arbitrary system commands.
This unpatched vulnerability enables remote code execution without authentication, directly threatening DIB systems relying on LoadMaster for network security. Organizations must immediately patch or replace affected hardware to prevent unauthorized system compromise and potential data exfiltration.
Shame score — A critical, actively exploited RCE vulnerability in a widely deployed network security product that allows unauthenticated remote access.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution.