Vulnerability Details and Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding a severe vulnerability affecting Progress Kemp LoadMaster devices. This command injection flaw, tracked as CVE-2023-1389, is being actively exploited by threat actors in the wild. The vulnerability allows unauthenticated attackers to execute arbitrary commands on the underlying operating system of vulnerable LoadMaster appliances. This means attackers can potentially gain full control over the affected devices without needing any prior access or credentials. The technical details reveal that the flaw lies within the Web UI component of LoadMaster. Specifically, improper sanitization of user-supplied input in certain Web UI functionalities allows for command injection. Attackers can craft malicious requests that, when processed by the vulnerable Web UI, trick the system into executing arbitrary operating system commands. The impact is severe, as LoadMaster appliances are often deployed at the network edge, acting as critical gateways for application traffic. Compromising these devices can lead to widespread network intrusion, data theft, and further lateral movement within an organization's infrastructure.
Affected Products and Mitigation Steps
According to Progress, the vulnerability affects Kemp LoadMaster appliances running specific versions of the LoadMaster firmware. The affected versions include:- LoadMaster firmware versions prior to 7.2.55
- LoadMaster firmware versions prior to 7.2.54.1
- LoadMaster firmware versions prior to 7.2.53.3
- Upgrade to LoadMaster firmware version 7.2.55 or later.
- Upgrade to LoadMaster firmware version 7.2.54.1 or later.
- Upgrade to LoadMaster firmware version 7.2.53.3 or later.
