CVE-2024-56134

CVSS 3.1 Score 8.4 of 10 (high)

Details

Published Feb 5, 2025
CWE ID 20

Summary

CVE-2024-56134 is an Authenticated OS Command Injection vulnerability impacting Progress LoadMaster versions 7.2.55.0 to 7.2.60.1 (inclusive), as well as 7.2.49.0 to 7.2.54.12 (inclusive), and all prior versions of LoadMaster, Multi-Tenant Hypervisor, and ECS. The flaw arises due to improper input validation, allowing attackers to inject and execute operating system commands. This vulnerability poses a significant risk, and affected organizations are urged to apply the necessary patches promptly to mitigate it.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share