CISA tags Progress Kemp LoadMaster flaw as exploited in attacks
A significant OS command injection that affects Progress Kemp LoadMaster is one of three new vulnerabilities that the U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added to its list of known exploited vulnerabilities (KEVs).
The vulnerability was fixed in an update published on February 21, 2024, after being identified by Rhino Security Labs and recorded as CVE-2024-1212. But this is the first time that its active exploitation in the wild has been documented.
The description of the bug states, "Progress Kemp LoadMaster has an OS command injection vulnerability that permits arbitrary system command execution by granting an unauthenticated, remote attacker access to the system via the LoadMaster management interface read more about CISA tags Progress Kemp LoadMast...

