Progress Software has recently patched several high-severity security vulnerabilities in its LoadMaster application delivery controller and load balancer solution. These flaws, if exploited, could allow authenticated attackers to execute system commands or download sensitive files from affected systems.
The identified vulnerabilities include:
– Four improper input validation flaws (CVE-2024-56131, CVE-2024-56132, CVE-2024-56133, and CVE-2024-56135) with CVSS scores of 8.4, enabling arbitrary command execution
– One vulnerability (CVE-2024-56134) with CVSS score 8.4, allowing unauthorized file downloads
Affected versions:
– LoadMaster 7.2.55.0 to 7.2.60.1 (Fixed in 7.2.61.0)
– LoadMaster 7.2.49.0 to 7.2.54.12 (Fixed in 7.2.54.13)
– LoadMaster 7.2.48.12 and prior (Upgrade required)
– Multi-Tenant LoadMaster 7.1.35.12 and prior (Fixed in 7.1.35.13)
While no active exploitation has been reported, Progress Software strongly recommends users update to the latest patched versions immediately, given the history of similar vulnerabilities being targeted by threat actors.
