Critical Security Update: Progress Software Fixes Dangerous LoadMaster Vulnerabilities That Enable System Attacks


Critical Security Flaws Patched in Progress Software’s LoadMaster

Progress Software has recently patched several high-severity security vulnerabilities in its LoadMaster application delivery controller and load balancer solution. These flaws, if exploited, could allow authenticated attackers to execute system commands or download sensitive files from affected systems.

The identified vulnerabilities include:
– Four improper input validation flaws (CVE-2024-56131, CVE-2024-56132, CVE-2024-56133, and CVE-2024-56135) with CVSS scores of 8.4, enabling arbitrary command execution
– One vulnerability (CVE-2024-56134) with CVSS score 8.4, allowing unauthorized file downloads

Affected versions:
– LoadMaster 7.2.55.0 to 7.2.60.1 (Fixed in 7.2.61.0)
– LoadMaster 7.2.49.0 to 7.2.54.12 (Fixed in 7.2.54.13)
– LoadMaster 7.2.48.12 and prior (Upgrade required)
– Multi-Tenant LoadMaster 7.1.35.12 and prior (Fixed in 7.1.35.13)

While no active exploitation has been reported, Progress Software strongly recommends users update to the latest patched versions immediately, given the history of similar vulnerabilities being targeted by threat actors.

Share This Article