GPU VulnDB

Database/Control plane, storage & DevOps

Progress Kemp LoadMaster (including Multi-Tenancy edition): A request handler fails to validate its input before

CVE-2024-7591Control plane, storage & DevOpscurated

Impact

A request handler fails to validate its input before passing it to a system call, giving an attacker OS command execution on the LoadMaster with no authentication at all. This explicitly affects the Multi-Tenancy edition — the product line built to let multiple tenants share one LoadMaster — so a single unauthenticated request can compromise the appliance underneath every tenant's virtual services on that instance.

Who can reach it

Fully remote and unauthenticated — a crafted request to the vulnerable API endpoint is sufficient, no login required.

What to do

Software upgrade to the fixed LoadMaster/Multi-Tenancy release per Kemp's advisory. Patch immediately given the unauthenticated, maximum-severity nature of this bug; if this instance is shared across tenants, treat any exposure window as a potential full-tenant-boundary breach and audit for signs of compromise, not just apply the patch.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.