TL;DR

Progress Software Kemp LoadMaster exposes a command injection flaw allowing RCE for authenticated users, rated CVSS 7.1.

What happened

['Authenticated network-adjacent attackers can exploit getcipherset command to inject and execute arbitrary commands']

Why it matters for ops

['Insecure handling of user input leading to remote code execution']

Mitigation

  • Apply security updates provided by Progress Software
  • Implement strict access controls and monitoring for affected systems

Action items

  • Update to the latest version of Kemp LoadMaster
  • Review and restrict permissions on getcipherset command usage

Detection IOCs

  • Unusual network traffic from affected devices
  • Unexpected process executions with elevated privileges

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-052/