Security Affairs
Hack One Robot, Reach the Next: Unitree G1 Security Flaws|Rhysida Ransomware Group Targets Berlin Government Ahead of Vote|Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator|Love Electric Breach: 877,000 Driver Records Offered for $600|Trump Targets Foreign Technology in New U.S. Power Grid Security Order|U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog|Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations|PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Hack One Robot, Reach the Next: Unitree G1 Security Flaws|Rhysida Ransomware Group Targets Berlin Government Ahead of Vote|Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator|Love Electric Breach: 877,000 Driver Records Offered for $600|Trump Targets Foreign Technology in New U.S. Power Grid Security Order|U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog|Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations|PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|
Advertisement

Ad Placeholder

Full Width × 90

Security

Progress Software fixed a maximum severity flaw in LoadMaster

Progress Software released an emergency to address a maximum severity vulnerability in its LoadMaster products. Progress Software released an emergency fix for a critical vulnerability, tracked as CVE-2024-7591, that affects its LoadMaster and LoadMaster Multi-Tenant (MT) Hypervisor products. The vulnerability is an improper input validation issue, that could allow an unauthenticated, remote attacker to access LoadMaster’s […]

Progress LoadMaster

Progress Software released an emergency to address a maximum severity vulnerability in its LoadMaster products.

Progress Software released an emergency fix for a critical vulnerability, tracked as CVE-2024-7591, that affects its LoadMaster and LoadMaster Multi-Tenant (MT) Hypervisor products.

The vulnerability is an improper input validation issue, that could allow an unauthenticated, remote attacker to access LoadMaster’s management interface using a specially crafted HTTP request.

“It is possible for unauthenticated, remote attackers who have access to the management interface of LoadMaster to issue a carefully crafted http request that will allow arbitrary system commands to be executed.” reads the advisory. “This vulnerability has been closed by sanitizing request user input to mitigate arbitrary system commands execution.”

Progress LoadMaster is a high-performance application delivery controller (ADC) and load balancer. It is designed to enhance the availability, scalability, performance, and security of business-critical applications and websites.

The vulnerability could enable an attacker to execute arbitrary commands on affected systems.

Below is the list of affected product versions:

 ProductAffected VersionsPatched VersionsRelease Date
LoadMaster7.2.60.0 and all prior versionsAdd-on Package
XML validation file
Sep 03 2024
Multi-Tenant Hypervisor7.1.35.11 and all prior versionsAdd-on Package
XML validation file
Sep 03 2024

Multi-Tenant LoadMaster (LoadMaster MT) is affected in case the following condition is met:

  • The individual instantiated LoadMaster VNFs are vulnerable and must be patched using the add-on listed above as soon as possible.
  • Note that the MT hypervisor or Manager node is also vulnerable and must be patched using the add-on listed above as soon as possible.

As reported by a user in the advisory comments, the addon package released by Progress doesn’t allow installation on the free version. 

The good news is that Progress is not aware of attacks in the wild exploiting this vulnerability.

“We have not received any reports that this vulnerability has been exploited and we are not aware of any direct impact to customers” states the advisory. “Nevertheless, we are encouraging all customers to upgrade their LoadMaster implementations as soon as possible to harden their environment. “

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Progress Software)