← Vulnerability feed

Vulnerability record · CVE-2024-2448 · published 22 March 2024

CVE-2024-2448: Progress LoadMaster UI OS Command Injection

Progress · Loadmaster

LoadMaster contains an OS command injection flaw (CWE-78) in a UI component. An authenticated UI user with any permission setting can inject shell commands, which execute with the privileges of the LoadMaster service. Because the affected component is reachable over the network and the flaw yields full compromise of confidentiality, integrity and availability, it is a serious post-authentication risk.

8.8 CVSS 3.1 High EPSS 55% · top 1.0% CWE-78 · OS command injection
8.8CVSS 3.1 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityNetwork-reachable authenticated command injection with high EPSS and full CIA impact, though no known exploitation or KEV listing.

What it is

LoadMaster contains an OS command injection flaw (CWE-78) in a UI component. An authenticated UI user with any permission setting can inject shell commands, which execute with the privileges of the LoadMaster service. Because the affected component is reachable over the network and the flaw yields full compromise of confidentiality, integrity and availability, it is a serious post-authentication risk.

Impact

An attacker with a low-privileged UI account can execute arbitrary OS commands on the LoadMaster appliance, gaining control of the device and potentially pivoting into the network it load-balances.

Attack surface

Reached over the network via the LoadMaster web UI (AV:N, AC:L). Authentication is required (PR:L) but no user interaction is needed (UI:N); any UI permission level is sufficient.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware association is recorded. EPSS is high (0.554, 98.99th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the vendor fix referenced in the Kemptechnologies security advisory for CVE-2024-2448 and CVE-2024-2449.
  • Restrict UI access to trusted management networks and disable or tightly scope non-administrative UI accounts.
  • Enforce MFA and strong unique credentials for all LoadMaster UI users.
  • Monitor and alert on unexpected shell or system command execution originating from the LoadMaster appliance.
  • If patching is delayed, isolate the management interface behind a jump host or VPN with strict ACLs.

Detection

  • Review LoadMaster UI and system logs for command strings or shell metacharacters in user-supplied fields.
  • Alert on child processes spawned by the LoadMaster web service (e.g., unexpected sh/bash invocations).
  • Baseline normal UI user activity and flag low-privileged accounts performing administrative or system-level actions.
  • Monitor outbound connections from the LoadMaster appliance to unusual destinations for signs of post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-2448 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed9.8CVE-2024-1212Progress LoadMaster management interface OS command injectionProgress Kemp LoadMaster contains an OS command injection flaw (CWE-78) in its management interface. An unauthenticated remote attacker can reach the…KEVEPSS 95%analysed9.8CVE-2024-8755Progress loadmaster improper input validation vulnerabilityImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects:  Product Affec…EPSS 1.2%8.8CVE-2025-1758Progress multi-tenant loadmaster stack-based buffer overflow vulnerabilityImproper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: Al…EPSS 4.8%8.8CVE-2014-5287Progress loadmaster injection vulnerabilityA Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI…EPSS 8.0%8.4CVE-2026-59687Progress connection manager for objectscale os command injection vulnerabilityAn OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows…EPSS 1.7%8.4CVE-2026-59688Progress connection manager for objectscale os command injection vulnerabilityAn OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows…EPSS 1.7%8.4CVE-2026-59686Progress connection manager for objectscale os command injection vulnerabilityAn OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2024-2448), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.