Progress Software released an emergency fix for a critical vulnerability (10/10) in its Loadmaster and LoadMaster Multi-Tenant Hypervisor products, which allows remote command execution by attackers.
CVE-2024-7591 is a flaw that allows remote, unauthenticated attackers to access Loadmaster’s management interface through a manipulated HTTP request due to improper input validation.
By infosecbulletin
/ Tuesday , December 3 2024
Cisco has released an updated security advisory about CVE-2014-2120, a vulnerability in the WebVPN login page of Cisco Adaptive Security...
Read More
By infosecbulletin
/ Tuesday , December 3 2024
A serious zero-day vulnerability has been found in TP-Link Archer, Deco, and Tapo routers, which could let attackers inject harmful...
Read More
By infosecbulletin
/ Monday , December 2 2024
IBM revealed several critical vulnerabilities in its Security Verify Access Appliance, which could pose serious security risks to users identified...
Read More
By infosecbulletin
/ Monday , December 2 2024
Cybersecurity researchers are alerting users about phishing email campaigns using a toolkit called "Rockstar 2FA" to steal Microsoft 365 account...
Read More
By infosecbulletin
/ Sunday , December 1 2024
A workshop on "DDoS use cases & solutions for government & BFSI" held at Bangladesh computer society premises on Saturday...
Read More
By infosecbulletin
/ Saturday , November 30 2024
Uganda’s finance ministry confirmed media reports that hackers breached the central bank’s systems and stole money, but refuted the claims...
Read More
By infosecbulletin
/ Friday , November 29 2024
CERT Germany and Zyxel have alerted about a serious vulnerability in Zyxel firewalls, identified as CVE-2024-11667. This flaw is being...
Read More
By infosecbulletin
/ Friday , November 29 2024
Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
By infosecbulletin
/ Thursday , November 28 2024
CERT-In has flagged a security vulnerability in Oracle’s Agile Product Lifecycle Management (PLM) software, identified as CVE-2024-21287 and cataloged as...
Read More
By infosecbulletin
/ Thursday , November 28 2024
On November 26th, Microsoft patched four vulnerabilities detected in Dynamics 365 Sales, the Partner.Microsoft.Com portal, Microsoft Copilot Studio and Azure...
Read More
“It is possible for unauthenticated, remote attackers who have access to the management interface of LoadMaster to issue a carefully crafted HTTP request that will allow arbitrary system commands to be executed,” reads the security bulletin.
“This vulnerability has been closed by sanitizing request user input to mitigate arbitrary system commands execution.”
Loadmaster is an application delivery controller that helps large organizations to improve app performance, manage network traffic, and maintain high service availability.
The MT Hypervisor is a specialized version of Loadmaster, tailored for multi-tenant environment. It enables the concurrent operation of multiple virtual network functions on a single hardware platform.
CVE-2024-7591 affects Loadmaster version 7.2.60.0 and earlier, as well as MT Hypervisor version 7.1.35.11 and all prior releases.