PT-2025-5723 · Progress · Loadmaster

CVE-2024-56132

·

Publicado

2025-02-05

·

Atualizado

2025-07-31

CVSS v3.1

8.4

Alta

VetorAV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LoadMaster versions 7.2.48.12 and earlier LoadMaster versions 7.2.49.0 through 7.2.54.12 LoadMaster versions 7.2.55.0 through 7.2.60.1 ECS versions prior to 7.2.60.1
Description The issue is related to improper input validation of authenticated users in Progress LoadMaster, allowing OS command injection. This can potentially lead to unauthorized system access and execution of malicious commands.
Recommendations For LoadMaster versions 7.2.48.12 and earlier, consider restricting access to sensitive system areas until a patch is available. For LoadMaster versions 7.2.49.0 through 7.2.54.12, restrict the use of vulnerable functions related to authenticated user input validation. For LoadMaster versions 7.2.55.0 through 7.2.60.1, temporarily disable any features that rely on user input validation to minimize the risk of OS command injection. For ECS versions prior to 7.2.60.1, apply similar restrictions as for LoadMaster to mitigate potential risks.

Correção

OS Command Injection

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-01595
CVE-2024-56132

Produtos afetados

Loadmaster