CVE-2024-6658: Progress LoadMaster

Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.0 (inclusive)    From 7.2.49.0 to 7.2.54.11 (inclusive)    7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.11 and all prior versions ECS All prior versions to 7.2.60.0 (inclusive)

Affected products

  • Progress LoadMaster: up to and including 7.2.48.12; from 7.2.49.0, before 7.2.54.12 (fixed in 7.2.54.12); from 7.2.55.0, before 7.2.60.1 (fixed in 7.2.60.1)
  • Progress Multi-Tenant LoadMaster: before 7.1.35.12 (fixed in 7.1.35.12)

Published 2024-09-12. Last modified 2026-06-17.