HTTP: Progress Kemp LoadMaster REST API Command Injection

This signature detects attempts to exploit a known vulnerability against Progress Kemp LoadMaster. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Affected Products

Progress loadmaster

Short Name
HTTP:CTS:PROGRES-KEMP-CMD-INJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
API CVE-2024-1212 CVE-2024-2389 CVE-2024-2448 Command Injection Kemp LoadMaster Progress REST
Release Date
05/07/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3760
False Positive
Unknown
Vendors

Progress

Found a potential security threat?