The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent emergency advisory confirming that threat actors are actively exploiting a critical zero-day vulnerability in Progress Kemp LoadMaster appliances. This elevates the issue from a theoretical risk to an immediate operational emergency for organizations relying on the platform for traffic distribution and application delivery.
Tracked as CVE-2024-47575 and assigned a maximum CVSS severity score of 9.8, the flaw is a command injection vulnerability located in the appliance’s management interface. Attackers can exploit it without authentication to remotely execute arbitrary system commands with root-level privileges. Given that LoadMaster devices typically operate at the network edge, a successful compromise grants adversaries complete control over the appliance, allowing them to intercept, modify, or drop sensitive traffic while establishing a privileged foothold for lateral movement into internal networks.
CISA's decision to add the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog confirms active exploitation in the wild. While this designation triggers mandatory patching deadlines for federal agencies and critical infrastructure, the technical severity warrants immediate action across all sectors. Progress Software has released corrective updates, with the definitive fix requiring administrators to upgrade to version 7.2.60.1 or later.
For infrastructure and security teams, remediating the flaw presents familiar operational challenges. Load balancers are foundational network components, and patching them often requires coordinated maintenance windows to prevent service disruption. While the vendor has suggested temporarily disabling the management interface as an interim mitigation, practitioners note this approach conflicts with environments relying on continuous administrative access, automated provisioning, or centralized monitoring. Security analysts therefore emphasize that applying the official vendor patch remains the only reliable remediation path.
The incident underscores the persistent security risks associated with proprietary network appliances managing high-value traffic. Unlike open-source alternatives that allow independent code auditing, closed-box infrastructure devices require organizations to rely entirely on vendor-supplied patches. For IT teams managing critical network stacks, this vulnerability serves as a practical reminder to enforce strict network segmentation around management planes, restrict administrative access to trusted jump hosts, and maintain rigorous patch management cycles. The advisory originates from U.S. authorities, but the architectural implications are universally applicable to infrastructure teams worldwide, including those in Hong Kong responsible for maintaining high-availability enterprise networks. Organizations should treat this disclosure as a priority trigger for immediate asset inventory and emergency patch deployment.
美國網絡安全和基礎設施安全局(CISA)發布緊急通告,確認威脅行為者正在積極利用 Progress Kemp LoadMaster 設備中的一個關鍵零日漏洞。此舉將該問題從理論風險提升為對依賴該平台進行流量分發和應用交付之組織的即時營運緊急狀態。
該漏洞編號為 CVE-2024-47575,CVSS 嚴重性評分為最高級別 9.8,屬於設備管理介面的命令注入漏洞。攻擊者可利用此漏洞,在未經認證的情況下遠程執行具備 root 權限的任意系統命令。鑒於 LoadMaster 設備通常在網絡邊緣運作,成功入侵將使攻擊者完全控制設備,從而攔截、篡改或丟棄敏感流量,並為橫向移動滲入內部網絡建立特權立足點。
CISA 將此漏洞納入其「已知被利用漏洞」目錄,證實了其在真實環境中的活躍利用狀態。儘管此指派為聯邦機構和關鍵基礎設施帶來了強制補丁修復的最後期限,但其技術嚴重性要求所有行業立即採取行動。Progress Software 已發布修正更新,最終修復方案要求管理員升級至 7.2.60.1 或更高版本。
對基礎設施和安全團隊而言,修復此漏洞面臨熟悉的營運挑戰。負載均衡器是基礎網絡組件,安裝補丁通常需要協調維護窗口以防止服務中斷。雖然供應商建議暫時禁用管理介面作為過渡緩解措施,但業界人士指出,此方法與依賴持續管理訪問、自動化配置或集中監控的環境相衝突。因此,安全分析師強調,套用官方供應商補丁仍是唯一可靠的修復途徑。
此事件突顯了管理高價值流量的專有網絡設備所帶來的持續性安全風險。與允許獨立代碼審計的開源替代方案不同,封閉式基礎設施設備要求組織完全依賴供應商提供的補丁。對於管理關鍵網絡堆疊的 IT 團隊而言,此漏洞實際提醒他們必須在管理平週圍實施嚴格的網絡分段,將管理訪問限制於受信任的跳板主機,並維持嚴格的補丁管理週期。通告雖源自美國當局,但其架構影響對全球基礎設施團隊皆適用,包括負責維護高可用性企業網絡的香港團隊。組織應將此披露視為優先觸發事項,立即進行資產盤點和緊急補丁部署。
