CVE-2014-5287 is a critical Bash script injection vulnerability affecting Kemp Load Master 7.1-16 and earlier, stemming from insufficient input sanitization in its Web User Interface (WUI). With a CVSS score of 8.8 (HIGH), this vulnerability allows unauthenticated attackers to execute arbitrary commands remotely with high impact on confidentiality, integrity, and availability, though user interaction is required. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry exists (EDB-36609) detailing multiple vulnerabilities in the affected product. Despite its high severity, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.1-16CPE matchmatch criteria | cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.