// For flags

CVE-2024-2449

LoadMaster Cross-Site Request Forgery (CSRF)

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a scenario, the CSRF payload hosted on the malicious site would execute HTTP transactions on behalf of the LoadMaster administrator.

Se ha identificado una vulnerabilidad de Cross-Site Request Forgery en LoadMaster. Es posible que un actor malintencionado, que tenga conocimiento previo de la IP o el nombre de host de un LoadMaster especĂ­fico, dirija a un administrador de LoadMaster autenticado a un sitio de terceros. En tal escenario, el payload CSRF alojado en el sitio malicioso ejecutarĂ­a transacciones HTTP en nombre del administrador de LoadMaster.

*Credits: Rhino Security Labs - David Yesland
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-03-14 CVE Reserved
  • 2024-03-22 CVE Published
  • 2024-08-12 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
  • CAPEC-62: Cross Site Request Forgery
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Progress Software
Search vendor "Progress Software"
LoadMaster
Search vendor "Progress Software" for product "LoadMaster"
>= 7.2.55.0 < 7.2.59.3 ( LoadMaster GA)
Search vendor "Progress Software" for product "LoadMaster" and version " >= 7.2.55.0 < 7.2.59.3 ( LoadMaster GA)"
en
Affected
Progress Software
Search vendor "Progress Software"
LoadMaster
Search vendor "Progress Software" for product "LoadMaster"
>= 7.2.49.0 < 7.2.54.9 ( LoadMaster LTSF)
Search vendor "Progress Software" for product "LoadMaster" and version " >= 7.2.49.0 < 7.2.54.9 ( LoadMaster LTSF)"
en
Affected
Progress Software
Search vendor "Progress Software"
LoadMaster
Search vendor "Progress Software" for product "LoadMaster"
>= 7.2.48.10 < 7.2.48.11 (LoadMaster LTS)
Search vendor "Progress Software" for product "LoadMaster" and version " >= 7.2.48.10 < 7.2.48.11 (LoadMaster LTS)"
en
Affected
Progress Software
Search vendor "Progress Software"
LoadMaster
Search vendor "Progress Software" for product "LoadMaster"
>= 7.1.35.10 < 7.1.35.11 (LoadMaster MT)
Search vendor "Progress Software" for product "LoadMaster" and version " >= 7.1.35.10 < 7.1.35.11 (LoadMaster MT)"
en
Affected