Kemptechnologies develops a focused line of load-balancing and web-application security appliances, including products such as LoadMaster and its web-application firewall, that sit in the critical path of application delivery and are deployed across enterprise networks. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the internet-facing nature of these devices and the access they command; the recurring weakness classes—including cross-site request forgery, cross-site scripting, injection flaws, and OS command injection—point to input-validation and output-encoding gaps characteristic of appliance web interfaces and configuration systems. Defenders should treat this vendor's security advisories as high-priority for internet-exposed instances; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kemptechnologies over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7591HIGH Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects:
* LoadMaster: 7.2.40.0 and above
* ECS: All versions
* Multi-Tenan | Sep 5, 2024 | 7.2 | 60 | NO | YES |
CVE-2014-5288HIGH A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages. | Feb 7, 2020 | 8.8 | 36 | NO | YES |
CVE-2018-9091CRITICAL A critical vulnerability in the KEMP LoadMaster Operating System (LMOS) 6.0.44 through 7.2.41.2 and Long Term Support (LTS) LMOS before 7.1.35.5 related to Session Management could | May 25, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-15524CRITICAL The Application Firewall Pack (AFP, aka Web Application Firewall) component on Kemp Load Balancer devices with software before 7.2.40.1 allows a Security Feature Bypass via an HTTP | Dec 19, 2017 | 9.1 | 28 | NO | NO |
CVE-2021-41823MEDIUM The Web Application Firewall (WAF) in Kemp LoadMaster 7.2.54.1 allows certain uses of onmouseover to bypass an XSS protection mechanism. | Jan 1, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kemptechnologies.
Media articles that mention a CVE ID that affects a product developed by Kemptechnologies — matched by CVE ID, not by vendor name.