CVE-2025-13447
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 27.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 27.22% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- progress/connection manager for objectscale* · progress/ecs connection manager · progress/loadmaster · progress/moveit waf · progress/multi-tenant hypervisor
- Source
- security@progress.com
References
- https://community.progress.com/s/article/Connection-Manager-for-ObjectScale-Vulnerabilities-CVE-2025-13444-CVE-2025-13447Vendor Advisory
- https://community.progress.com/s/article/ECS-Connection-Manager-Vulnerabilities-CVE-2025-13444-CVE-2025-13447Vendor Advisory
- https://community.progress.com/s/article/LoadMaster-Vulnerabilities-CVE-2025-13444-CVE-2025-13447Vendor Advisory
- https://community.progress.com/s/article/MOVEit-WAF-Vulnerabilities-CVE-2025-13444-CVE-2025-13447Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.