Impact
An OS Command Injection flaw (CWE‑78) exists in the management interface of Progress Software's LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. An attacker who is authenticated and holds high‑level privileges can supply arbitrary shell commands that the appliance then executes. This leads to total control over the operating system, allowing data exfiltration, installation of malware, or denial of service against the affected infrastructure.
Affected Systems
The affected products include Progress Software's LoadMaster, ECS Connection Manager, Object Scale Connection Manager and MOVEit WAF. No specific version ranges are listed in the CNA data; therefore it is unclear which build numbers are vulnerable. Any deployment of the listed products that has not yet applied the vendor’s security fix should be considered at risk.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability. The EPSS score of 0.00734 (<1%) indicates a very low probability of exploitation, and the lack of a KEV listing suggests it has not yet been widely abused in the wild. The attacker must be authenticated with high‑level privileges and is expected to use the web‑based management interface; this is inferred from the description and is not explicitly stated in the advisory.
OpenCVE Enrichment