OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
| Vendor | Product | Versions |
|---|---|---|
| progress | connection_manager_for_objectscale | V7.2.60.0, V7.2.45.12, V7.2.60.0, V7.2.60.0, V7.2.60.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| kemp | loadmaster | cert_advisory | 90% |
| progress | moveit_web_application_firewall | cve_cpe | 95% |
| progress | ecs_connection_manager | cve_cpe | 95% |
| progress | loadmaster | cve_cpe | 95% |
Updated affected versions to include v7.2.63.2 and v7.2.54.18.
Updated description with more technical detail and corrected exploit availability to false.
Initial creation