// For flags

CVE-2024-3544

LoadMaster Hardcoded SSH Key

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to the same network of one of the machines in the HA or Cluster group. This vulnerability has been closed by enhancing LoadMaster partner communications to require a shared secret that must be exchanged between the partners before communication can proceed.

Los atacantes no autenticados pueden realizar acciones utilizando claves privadas SSH conociendo la dirección IP y teniendo acceso a la misma red de una de las máquinas del grupo HA o Cluster. Esta vulnerabilidad se ha solucionado mejorando las comunicaciones con los socios de LoadMaster para requerir un secreto compartido que debe intercambiarse entre los socios antes de que pueda continuar la comunicación.

*Credits: Agenzia per la Cybersicurezza Nazionale (ACN)
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-04-09 CVE Reserved
  • 2024-05-02 CVE Published
  • 2024-05-03 EPSS Updated
  • 2024-08-01 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-798: Use of Hard-coded Credentials
CAPEC
  • CAPEC-115: Authentication Bypass
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Progress Software Corporation
Search vendor "Progress Software Corporation"
LoadMaster
Search vendor "Progress Software Corporation" for product "LoadMaster"
< 7.2.59.4
Search vendor "Progress Software Corporation" for product "LoadMaster" and version " < 7.2.59.4"
en
Affected
Progress Software Corporation
Search vendor "Progress Software Corporation"
LoadMaster
Search vendor "Progress Software Corporation" for product "LoadMaster"
< 7.2.54.10
Search vendor "Progress Software Corporation" for product "LoadMaster" and version " < 7.2.54.10"
en
Affected
Progress Software Corporation
Search vendor "Progress Software Corporation"
LoadMaster
Search vendor "Progress Software Corporation" for product "LoadMaster"
< 7.2.48.12
Search vendor "Progress Software Corporation" for product "LoadMaster" and version " < 7.2.48.12"
en
Affected