OS Command Injection Vulnerability in LoadMaster

CVE-2024-2448
8.4HIGH

Key Information

Status
Loadmaster
Vendor
CVE Published:
22 March 2024

Summary

An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.

Affected Version(s)

LoadMaster <= 7.2.55.0

LoadMaster < 7.2.59.3 ( LoadMaster GA)

LoadMaster < 7.2.54.9 ( LoadMaster LTSF)

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Rhino Security Labs - David Yesland
.