{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2024-1212",
  "revision": 1,
  "title": "Progress Kemp LoadMaster — unauthenticated command execution",
  "summary": "The management interface of Progress Kemp LoadMaster lets an unauthenticated attacker reach the system and run commands on it, which hands them the load balancer sitting in front of the applications.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.95388,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2024-11-18",
    "prerequisites": "Network access to the management interface; no credentials needed."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1059"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Apply the vendor fix for this now; exploitation probability is near certain, so keep the management interface off the internet and rotate its credentials.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-1212",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2024-1212",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-1212",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1212",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    }
  ],
  "published_at": "2024-02-21T18:15:50.417Z",
  "issued_at": "2026-09-24T12:03:01.274Z",
  "tags": [
    "progress",
    "loadmaster",
    "load-balancer",
    "command-injection",
    "kev"
  ]
}
