Vulnerability record · CVE-2024-1212 · published 21 February 2024
CVE-2024-1212: Progress LoadMaster management interface OS command injection
Progress · Loadmaster
Progress Kemp LoadMaster contains an OS command injection flaw (CWE-78) in its management interface. An unauthenticated remote attacker can reach the interface and execute arbitrary system commands. Because the interface is network-exposed and no credentials are required, this is a severe pre-auth remote code execution issue.
Description
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable command execution with CVSS 9.8, KEV listing and near-maximum EPSS makes this an urgent patch target.
What it is
Progress Kemp LoadMaster contains an OS command injection flaw (CWE-78) in its management interface. An unauthenticated remote attacker can reach the interface and execute arbitrary system commands. Because the interface is network-exposed and no credentials are required, this is a severe pre-auth remote code execution issue.
Impact
An attacker gains arbitrary command execution on the LoadMaster appliance, effectively full control of the device, including its configuration and any traffic or credentials it handles.
Attack surface
Reachable over the network via the LoadMaster management interface (CVSS vector AV:N/PR:N/UI:N), so no authentication and no user interaction are needed. The description does not specify which management port or endpoint is involved.
Exploitation
CVE-2024-1212 is listed in CISA KEV (added 2024-11-18, due 2024-12-09) and has an EPSS 30-day probability of 0.954 (99.9th percentile), indicating active exploitation is expected or observed. No ransomware campaign use is recorded.
What to do
- Apply the vendor patches referenced in the LoadMaster release notice (LMOS 7.2.59.2, 7.2.54.8, 7.2.48.10) or later.
- If patching is not immediately possible, follow the vendor security advisory mitigations or discontinue use of the product per CISA KEV guidance.
- Restrict access to the LoadMaster management interface to trusted management networks only; do not expose it to the internet.
- Rotate any credentials and secrets stored or processed by affected LoadMaster appliances.
- Monitor vendor advisories for updated fixed versions and confirm the deployed build.
Detection
- Review LoadMaster management interface access logs for unexpected or anomalous requests, especially from untrusted source IPs.
- Hunt for command execution artifacts or unexpected child processes spawned by the LoadMaster management service.
- Alert on management interface connections originating outside approved administrative networks.
- Correlate network telemetry for scanning or exploitation attempts against the LoadMaster management port.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-1212 to the Known Exploited Vulnerabilities catalog on 18 November 2024 as "Progress Kemp LoadMaster OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 9 December 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-1212 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-1212), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.