← Back to CVE List
Vulnerability Intelligence Report
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection

CVE-2024-7591

Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above

Nuclei Template
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:44.07%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
Progress LoadMaster 7.2.40.0 < 7.2.60.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Nuclei Template
SCANNER AVAILABLE
EPSS Score
44.069%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityProgress Software Corporation · Vendor · USA
Reserved2024-08-07T14:49:00
Published2024-09-05T17:16:30
Last Updated2025-02-18T15:36:20

LINK COPIED TO CLIPBOARD