{"id":168192,"date":"2024-09-09T05:28:10","date_gmt":"2024-09-09T05:28:10","guid":{"rendered":"https:\/\/securityaffairs.com\/?p=168192"},"modified":"2024-09-09T10:19:50","modified_gmt":"2024-09-09T10:19:50","slug":"progress-software-emergency-loadmaster-flaw","status":"publish","type":"post","link":"https:\/\/securityaffairs.com\/168192\/security\/progress-software-emergency-loadmaster-flaw.html","title":{"rendered":"Progress Software fixed a maximum severity flaw in LoadMaster"},"content":{"rendered":"
<\/div>\n

Progress Software released an emergency to address a maximum severity vulnerability in its LoadMaster products.<\/h2>\n\n\n\n

Progress Software released an emergency fix for a critical vulnerability, tracked as CVE-2024-7591<\/a>, that affects its LoadMaster and LoadMaster Multi-Tenant (MT) Hypervisor products.<\/p>\n\n\n\n

The vulnerability is an improper input validation issue, that could allow an unauthenticated, remote attacker to access LoadMaster\u2019s management interface using a specially crafted HTTP request. <\/p>\n\n\n\n

“It is possible for unauthenticated, remote attackers who have access to the management interface of LoadMaster to issue a carefully crafted http request that will allow arbitrary system commands to be executed.” reads the advisory<\/a>. “This vulnerability has been closed by sanitizing request user input to mitigate arbitrary system commands execution.”<\/em><\/p>\n\n\n\n

Progress LoadMaster is a high-performance application delivery controller (ADC) and load balancer. It is designed to enhance the availability, scalability, performance, and security of business-critical applications and websites.<\/p>\n\n\n\n

The vulnerability could enable an attacker to execute arbitrary commands on affected systems.<\/p>\n\n\n\n

Below is the list of affected product versions:<\/p>\n\n\n\n

 Product<\/strong><\/td>Affected Versions<\/strong><\/td>Patched Versions<\/strong><\/td>Release Date<\/strong><\/td><\/tr>
LoadMaster<\/strong><\/td>7.2.60.0 and all prior versions<\/td>Add-on Package<\/a>
XML validation file<\/a><\/td>
Sep 03 2024<\/td><\/tr>
Multi-Tenant Hypervisor<\/strong><\/td>7.1.35.11 and all prior versions<\/td>Add-on Package<\/a>
XML validation file<\/a><\/td>
Sep 03 2024<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n

Multi-Tenant LoadMaster (LoadMaster MT) is affected in case the following condition is met:<\/p>\n\n\n\n