CVE-2024-3544
LoadMaster Hardcoded SSH Key
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to the same network of one of the machines in the HA or Cluster group. This vulnerability has been closed by enhancing LoadMaster partner communications to require a shared secret that must be exchanged between the partners before communication can proceed.
Los atacantes no autenticados pueden realizar acciones utilizando claves privadas SSH conociendo la dirección IP y teniendo acceso a la misma red de una de las máquinas del grupo HA o Cluster. Esta vulnerabilidad se ha solucionado mejorando las comunicaciones con los socios de LoadMaster para requerir un secreto compartido que debe intercambiarse entre los socios antes de que pueda continuar la comunicación.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-04-09 CVE Reserved
- 2024-05-02 CVE Published
- 2024-05-03 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
- CAPEC-115: Authentication Bypass
References (2)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Progress Software Corporation Search vendor "Progress Software Corporation" | LoadMaster Search vendor "Progress Software Corporation" for product "LoadMaster" | < 7.2.59.4 Search vendor "Progress Software Corporation" for product "LoadMaster" and version " < 7.2.59.4" | en |
Affected
| ||||||
Progress Software Corporation Search vendor "Progress Software Corporation" | LoadMaster Search vendor "Progress Software Corporation" for product "LoadMaster" | < 7.2.54.10 Search vendor "Progress Software Corporation" for product "LoadMaster" and version " < 7.2.54.10" | en |
Affected
| ||||||
Progress Software Corporation Search vendor "Progress Software Corporation" | LoadMaster Search vendor "Progress Software Corporation" for product "LoadMaster" | < 7.2.48.12 Search vendor "Progress Software Corporation" for product "LoadMaster" and version " < 7.2.48.12" | en |
Affected
|