CVE-2024-7591
CRITICAL NUCLEIKemp LoadMaster 7.2.40.0-7.2.59.9 and Multi-Tenant Hypervisor Firmware 7.1.35.4-7.1.35.10 - OS Command Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-7591. PoCs published by butyraldehyde. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a Python-based PoC for CVE-2024-7591, targeting Kemp LoadMaster for remote code execution via command injection in the login endpoint. The exploit encodes commands using a specific ASCII-based scheme and leverages session tokens extracted from the homepage.
Description
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above
Exploits (1)
This repository contains a Python-based PoC for CVE-2024-7591, targeting Kemp LoadMaster for remote code execution via command injection in the login endpoint. The exploit encodes commands using a specific ASCII-based scheme and leverages session tokens extracted from the homepage.
Nuclei Templates (1)
html:"Kemp Login Screen"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H