Impact
An OS Command Injection flaw exists in the backup restore functionality of Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. An authenticated attacker possessing high‑level privileges can cause the appliance to run arbitrary operating‑system commands, leading to a full system compromise. This weakness is a classic CWE-78 input‑to‑command injection.
Affected Systems
The vulnerability affects several Progress Software products: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. No specific version information is available in the advisory, so all current releases may be at risk.
Risk and Exploitability
The CVSS score of 8.4 classifies this as a high‑severity flaw. While the EPSS score is < 1%, the KEV listing indicates no widespread exploitation has been observed yet, but the need for authentic high privileges narrows the threat to internal users with advanced access. Exploitation would occur by triggering the backup restore path from an elevated account, causing remote command execution on the appliance.
OpenCVE Enrichment