← Vulnerability feed

Vulnerability record · CVE-2024-1212 · published 21 February 2024

CVE-2024-1212: Progress LoadMaster management interface OS command injection

Progress · Loadmaster

Progress Kemp LoadMaster contains an OS command injection flaw (CWE-78) in its management interface. An unauthenticated remote attacker can reach the interface and execute arbitrary system commands. Because the interface is network-exposed and no credentials are required, this is a severe pre-auth remote code execution issue.

9.8 CVSS 3.1 Critical CISA KEV since 18 Nov 2024 EPSS 95% · top 0.1% CWE-78 · OS command injection
9.8CVSS 3.1 base score
95%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References
13 Jul 2026Last modified by NVD

Description

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable command execution with CVSS 9.8, KEV listing and near-maximum EPSS makes this an urgent patch target.

What it is

Progress Kemp LoadMaster contains an OS command injection flaw (CWE-78) in its management interface. An unauthenticated remote attacker can reach the interface and execute arbitrary system commands. Because the interface is network-exposed and no credentials are required, this is a severe pre-auth remote code execution issue.

Impact

An attacker gains arbitrary command execution on the LoadMaster appliance, effectively full control of the device, including its configuration and any traffic or credentials it handles.

Attack surface

Reachable over the network via the LoadMaster management interface (CVSS vector AV:N/PR:N/UI:N), so no authentication and no user interaction are needed. The description does not specify which management port or endpoint is involved.

Exploitation

CVE-2024-1212 is listed in CISA KEV (added 2024-11-18, due 2024-12-09) and has an EPSS 30-day probability of 0.954 (99.9th percentile), indicating active exploitation is expected or observed. No ransomware campaign use is recorded.

What to do

  • Apply the vendor patches referenced in the LoadMaster release notice (LMOS 7.2.59.2, 7.2.54.8, 7.2.48.10) or later.
  • If patching is not immediately possible, follow the vendor security advisory mitigations or discontinue use of the product per CISA KEV guidance.
  • Restrict access to the LoadMaster management interface to trusted management networks only; do not expose it to the internet.
  • Rotate any credentials and secrets stored or processed by affected LoadMaster appliances.
  • Monitor vendor advisories for updated fixed versions and confirm the deployed build.

Detection

  • Review LoadMaster management interface access logs for unexpected or anomalous requests, especially from untrusted source IPs.
  • Hunt for command execution artifacts or unexpected child processes spawned by the LoadMaster management service.
  • Alert on management interface connections originating outside approved administrative networks.
  • Correlate network telemetry for scanning or exploitation attempts against the LoadMaster management port.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-1212 to the Known Exploited Vulnerabilities catalog on 18 November 2024 as "Progress Kemp LoadMaster OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 9 December 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-1212 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed9.8CVE-2024-8755Progress loadmaster improper input validation vulnerabilityImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects:  Product Affec…EPSS 1.2%8.8CVE-2025-1758Progress multi-tenant loadmaster stack-based buffer overflow vulnerabilityImproper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: Al…EPSS 4.8%8.8CVE-2024-2448Progress LoadMaster UI OS Command InjectionLoadMaster contains an OS command injection flaw (CWE-78) in a UI component. An authenticated UI user with any permission setting can inject shell co…EPSS 55%analysed8.8CVE-2014-5287Progress loadmaster injection vulnerabilityA Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI…EPSS 8.0%8.4CVE-2026-59687Progress connection manager for objectscale os command injection vulnerabilityAn OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows…EPSS 1.7%8.4CVE-2026-59688Progress connection manager for objectscale os command injection vulnerabilityAn OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows…EPSS 1.7%8.4CVE-2026-59686Progress connection manager for objectscale os command injection vulnerabilityAn OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2024-1212), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.