Vulnerability record · CVE-2024-2448 · published 22 March 2024
CVE-2024-2448: Progress LoadMaster UI OS Command Injection
Progress · Loadmaster
LoadMaster contains an OS command injection flaw (CWE-78) in a UI component. An authenticated UI user with any permission setting can inject shell commands, which execute with the privileges of the LoadMaster service. Because the affected component is reachable over the network and the flaw yields full compromise of confidentiality, integrity and availability, it is a serious post-authentication risk.
Description
An OS command injection vulnerability has been identified in LoadMaster. An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityNetwork-reachable authenticated command injection with high EPSS and full CIA impact, though no known exploitation or KEV listing.
What it is
LoadMaster contains an OS command injection flaw (CWE-78) in a UI component. An authenticated UI user with any permission setting can inject shell commands, which execute with the privileges of the LoadMaster service. Because the affected component is reachable over the network and the flaw yields full compromise of confidentiality, integrity and availability, it is a serious post-authentication risk.
Impact
An attacker with a low-privileged UI account can execute arbitrary OS commands on the LoadMaster appliance, gaining control of the device and potentially pivoting into the network it load-balances.
Attack surface
Reached over the network via the LoadMaster web UI (AV:N, AC:L). Authentication is required (PR:L) but no user interaction is needed (UI:N); any UI permission level is sufficient.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware association is recorded. EPSS is high (0.554, 98.99th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the vendor fix referenced in the Kemptechnologies security advisory for CVE-2024-2448 and CVE-2024-2449.
- Restrict UI access to trusted management networks and disable or tightly scope non-administrative UI accounts.
- Enforce MFA and strong unique credentials for all LoadMaster UI users.
- Monitor and alert on unexpected shell or system command execution originating from the LoadMaster appliance.
- If patching is delayed, isolate the management interface behind a jump host or VPN with strict ACLs.
Detection
- Review LoadMaster UI and system logs for command strings or shell metacharacters in user-supplied fields.
- Alert on child processes spawned by the LoadMaster web service (e.g., unexpected sh/bash invocations).
- Baseline normal UI user activity and flag low-privileged accounts performing administrative or system-level actions.
- Monitor outbound connections from the LoadMaster appliance to unusual destinations for signs of post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-2448 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-2448), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.