{"id":"CVE-2024-1212","title":"Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.","summary":"Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.","severity":"critical","cvss":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-78","CWE-78"],"vendor":"progress","product":"loadmaster","affected":["loadmaster >= 7.2.48.1, < 7.2.48.10","loadmaster >= 7.2.54.0, < 7.2.54.8","loadmaster >= 7.2.55.0, < 7.2.59.2"],"patched":["loadmaster 7.2.59.2"],"published":"2024-02-21","updated":"2026-07-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-1212","references":[{"url":"https://freeloadbalancer.com/","label":"security@progress.com"},{"url":"https://kemptechnologies.com/","label":"security@progress.com"},{"url":"https://support.kemptechnologies.com/hc/en-us/articles/23878931058445-LoadMaster-Security-Vulnerability-CVE-2024-1212","label":"security@progress.com"},{"url":"https://support.kemptechnologies.com/hc/en-us/articles/24325072850573-Release-Notice-LMOS-7-2-59-2-7-2-54-8-7-2-48-10-CVE-2024-1212","label":"security@progress.com"},{"url":"https://freeloadbalancer.com/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://kemptechnologies.com/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.kemptechnologies.com/hc/en-us/articles/23878931058445-LoadMaster-Security-Vulnerability-CVE-2024-1212","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.kemptechnologies.com/hc/en-us/articles/24325072850573-Release-Notice-LMOS-7-2-59-2-7-2-54-8-7-2-48-10-CVE-2024-1212","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1212","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.95388,"epssPercentile":0.99867,"kev":true,"kevDateAdded":"2024-11-18","kevDueDate":"2024-12-09","kevRansomware":false,"exploited":true,"ingestedAt":"2026-07-13T20:28:57.814Z","exploits":{"github":2,"githubRepos":["https://github.com/Chocapikk/CVE-2024-1212","https://github.com/r0otk3r/CVE-2024-1212"],"metasploit":["exploit/linux/http/progress_kemp_loadmaster_unauth_cmd_injection","exploit/linux/local/progress_kemp_loadmaster_sudo_privesc_2024"],"nuclei":["CVE-2024-1212"],"checkedAt":"2026-09-21T15:26:16.066Z"},"exploitAvailable":true,"slug":"CVE-2024-1212","body":"## Overview\n\nUnauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.\n\n## Affected\n\n- `loadmaster >= 7.2.48.1, < 7.2.48.10`\n- `loadmaster >= 7.2.54.0, < 7.2.54.8`\n- `loadmaster >= 7.2.55.0, < 7.2.59.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `loadmaster 7.2.59.2`","depth":"hadal","depthScore":99,"depthScoreParts":{"impact":55,"likelihood":19.1,"exploitation":25,"ransomware":0},"changes":[{"seq":4685,"id":"CVE-2024-1212","ts":1788887199678,"field":"exploit_available","old":"false","new":"true"},{"seq":3568,"id":"CVE-2024-1212","ts":1788886316175,"field":"exploit_available","old":"true","new":"false"},{"seq":2422,"id":"CVE-2024-1212","ts":1788882984943,"field":"exploit_available","old":"false","new":"true"},{"seq":1451,"id":"CVE-2024-1212","ts":1788882398200,"field":"exploit_available","old":"true","new":"false"},{"seq":565,"id":"CVE-2024-1212","ts":1788881834529,"field":"exploit_available","old":"false","new":"true"}]}