CVE-2024-1212

Progress Software LoadMaster, kemptechnologies loadmaster

Published 21 Feb 2024 · updated 13 Jul 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 18 Nov 2024, with a remediation deadline of 9 Dec 2024 for US federal agencies.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

References