Progress LoadMaster Security Update – 09 September 2024

Progress has released a security update to address a critical vulnerability affecting LoadMaster 7.2.60.0 and all prior versions and Multi-Tenant Hypervisor 7.1.35.11 and all prior versions.

The addressed vulnerability could allow the unauthenticated remote attacker to execute arbitrary code, and gain access to the affected LoadMaster’s management interface using a specially crafted HTTP request.

Progress LoadMaster Code Execution Vulnerability (CVE-2024-7591):

  • CVSS: 10
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2024-7591

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Progress LoadMaster Security Update

References