VYPR
Vendor

Kemp

Products
8
CVEs
12
Across products
17
Status
Private

Products

8

Recent CVEs

12
  • CVE-2024-1212CriKEVFeb 21, 2024
    risk 0.88cvss 10.0epss 0.95

    Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

  • CVE-2024-7591CriSep 5, 2024
    risk 0.69cvss 10.0epss 0.44

    Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above

  • CVE-2018-9091CriMay 25, 2018
    risk 0.64cvss 9.8epss 0.03

    A critical vulnerability in the KEMP LoadMaster Operating System (LMOS) 6.0.44 through 7.2.41.2 and Long Term Support (LTS) LMOS before 7.1.35.5 related to Session Management could allow an unauthenticated, remote attacker to bypass security protections, gain system privileges,…

  • CVE-2014-5287HigJan 8, 2020
    risk 0.61cvss 8.8epss 0.08

    A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).

  • CVE-2014-5288HigFeb 7, 2020
    risk 0.60cvss 8.8epss 0.02

    A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.

  • CVE-2024-2448HigMar 22, 2024
    risk 0.59cvss 8.4epss 0.55

    An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.

  • CVE-2017-15524CriDec 19, 2017
    risk 0.59cvss 9.1epss 0.01

    The Application Firewall Pack (AFP, aka Web Application Firewall) component on Kemp Load Balancer devices with software before 7.2.40.1 allows a Security Feature Bypass via an HTTP POST request.

  • CVE-2024-2449HigMar 22, 2024
    risk 0.50cvss 7.5epss 0.13

    A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a…

  • CVE-2023-29929HigAug 21, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability found in Kemptechnologies Loadmaster before v.7.2.60.0 allows a remote attacker to casue a denial of service via the libkemplink.so, isreverse library.

  • CVE-2024-3544HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to the same network of one of the machines in the HA or Cluster group. This vulnerability has been closed by enhancing LoadMaster partner communications to require…

  • CVE-2023-26100MedApr 21, 2023
    risk 0.40cvss 6.1epss 0.00

    In Progress Flowmon before 12.2.0, an application endpoint failed to sanitize user-supplied input. A threat actor could leverage a reflected XSS vulnerability to execute arbitrary code within the context of a Flowmon user's web browser.

  • CVE-2021-41823MedJan 1, 2023
    risk 0.40cvss 6.1epss 0.00

    The Web Application Firewall (WAF) in Kemp LoadMaster 7.2.54.1 allows certain uses of onmouseover to bypass an XSS protection mechanism.