Critical Progress LoadMaster flaw now actively exploited in attacks

Summary

CISA has issued a warning that threat actors are actively exploiting a critical command injection vulnerability in Progress Kemp LoadMaster. This flaw allows attackers to remotely execute arbitrary commands on affected systems.

IFF Assessment

FOE

The active exploitation of a critical vulnerability signifies a direct threat to organizations, making it bad news for defenders.

Severity

9.8 Critical (AI Estimated)

The vulnerability allows for remote command injection, which is a severe attack vector that can lead to complete system compromise. Given its critical severity and active exploitation, a high CVSS score is warranted.

Defender Context

Organizations using Progress Kemp LoadMaster devices must prioritize patching or implementing workarounds immediately to prevent compromise. Defenders should monitor network traffic for indicators of compromise related to command injection attempts.

Read Full Story →