Web_Logo
Remote Support
Security Alert: Critical Flaw in Kemp LoadMaster Under Attack
Home » Security Alerts  »  Security Alert: Critical Flaw in Kemp LoadMaster Under Attack

Security Alert: Critical Flaw in Kemp LoadMaster Under Attack

A critical security flaw in Progress Kemp LoadMaster, a load balancer appliance used by many businesses, is being actively exploited right now.

  • What it is: An unauthenticated attacker can send a specially crafted request to the appliance and run commands on it without needing a username or password.
  • Who is affected: Businesses running Kemp LoadMaster GA version 7.2.63.1 or earlier, or LTSF version 7.2.54.17 or earlier, particularly where the API feature is enabled.
  • What the risk is: A successful attack can give an outsider full control of the appliance, which sits in front of critical business systems and network traffic.
  • What action is needed: Upgrade to GA version 7.2.63.2 or LTSF version 7.2.54.18 as soon as possible. If you are unsure which version you are running, check with your IT provider today.

We recommend confirming your patch level immediately given active exploitation is already underway.

Source: The Hacker News