« Volver al listado

CVE-2024-2449

Estado: AnalizadaAlta (7.5)—

A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a scenario, the CSRF payload hosted on the malicious site would execute HTTP transactions on behalf of the LoadMaster administrator.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-2449",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-2449",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-03-22T14:59:39.862131Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@progress.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "security@progress.com",
      "affectedData": [
        {
          "vendor": "Progress Software",
          "modules": [
            "LoadMaster",
            "Multi-Tenancy",
            "ECS Connection Manager",
            "LM 360 Connector"
          ],
          "product": "LoadMaster",
          "versions": [
            {
              "status": "affected",
              "version": "7.2.55.0",
              "lessThan": "7.2.59.3 ( LoadMaster GA)",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.2.49.0",
              "lessThan": "7.2.54.9 ( LoadMaster LTSF)",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.2.48.10",
              "lessThan": "7.2.48.11 (LoadMaster LTS)",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.1.35.10",
              "lessThan": "7.1.35.11 (LoadMaster MT)",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:kemptechnologies:loadmaster:*:*:*:*:*:*:*:*"
          ],
          "vendor": "kemptechnologies",
          "product": "loadmaster",
          "versions": [
            {
              "status": "affected",
              "version": "7.2.55.0",
              "lessThan": "7.2.59.3",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:progress:loadmaster:*:*:*:*:lts:*:*:*"
          ],
          "vendor": "progress",
          "product": "loadmaster",
          "versions": [
            {
              "status": "affected",
              "version": "7.2.48.10",
              "lessThan": "7.2.48.11",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:progress:loadmaster:*:*:*:*:ltsf:*:*:*"
          ],
          "vendor": "progress",
          "product": "loadmaster",
          "versions": [
            {
              "status": "affected",
              "version": "7.2.49.0",
              "lessThan": "7.2.54.9",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:progress:loadmaster:*:*:*:*:ml:*:*:*"
          ],
          "vendor": "progress",
          "product": "loadmaster",
          "versions": [
            {
              "status": "affected",
              "version": "7.1.35.10",
              "lessThan": "7.1.35.11",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-03-22T14:15:09.210",
  "references": [
    {
      "url": "https://progress.com/loadmaster",
      "tags": [
        "Broken Link"
      ],
      "source": "security@progress.com"
    },
    {
      "url": "https://support.kemptechnologies.com/hc/en-us/articles/25119767150477-LoadMaster-Security-Vulnerabilities-CVE-2024-2448-and-CVE-2024-2449",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@progress.com"
    },
    {
      "url": "https://progress.com/loadmaster",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.kemptechnologies.com/hc/en-us/articles/25119767150477-LoadMaster-Security-Vulnerabilities-CVE-2024-2448-and-CVE-2024-2449",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@progress.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a scenario, the CSRF payload hosted on the malicious site would execute HTTP transactions on behalf of the LoadMaster administrator."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad de Cross-Site Request Forgery en LoadMaster. Es posible que un actor malintencionado, que tenga conocimiento previo de la IP o el nombre de host de un LoadMaster específico, dirija a un administrador de LoadMaster autenticado a un sitio de terceros. En tal escenario, el payload CSRF alojado en el sitio malicioso ejecutaría transacciones HTTP en nombre del administrador de LoadMaster."
    }
  ],
  "lastModified": "2026-06-17T07:24:33.527",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:progress:loadmaster:*:*:*:*:ltsf:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09E601FC-0D63-44B7-8726-DA512D075139",
              "versionEndExcluding": "7.2.54.9",
              "versionStartIncluding": "7.2.49.0"
            },
            {
              "criteria": "cpe:2.3:a:progress:loadmaster:*:*:*:*:ga:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F95CC892-C725-49BE-AC30-3AB2C1547517",
              "versionEndExcluding": "7.2.59.3",
              "versionStartIncluding": "7.2.55.0"
            },
            {
              "criteria": "cpe:2.3:a:progress:loadmaster:7.1.35.10:*:*:*:mt:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F615B26-D735-4A95-9D04-D434B61CFB38"
            },
            {
              "criteria": "cpe:2.3:a:progress:loadmaster:7.2.48.10:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8DDDA906-6A2C-4662-B3EC-6406BC32370D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@progress.com"
}