KEVIntel
10.0
CVSS
Critical

CVE-2024-1212

PUBLISHED

LoadMaster Pre-Authenticated OS Command Injection

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
Progress Software
Product
LoadMaster
Published
Feb 21, 2024
EPSS

Description

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

cisa nuclei_scanner metasploit nessus_scanner

CVSS scores

CVSS v3.1 10.0 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2024-11-18 00:00:00 UTC · Source

Proof of concept available

Recorded 2024-03-19 22:23:18 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Nov 18, 2024

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

progress_kemp_loadmaster_unauth_cmd_injection

metasploit · Created Unknown

Metasploit module for CVE-2024-1212

Chocapikk/CVE-2024-1212

github · Created 2024-03-19 22:23:18 UTC · 17 stars

Unauthenticated Command Injection In Progress Kemp LoadMaster

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit