Database/Control plane, storage & DevOps

Kemp LoadMaster (LMOS): A flaw in session management lets a remote, unauthenticated attacker bypass the LoadMaster's
Impact
A flaw in session management lets a remote, unauthenticated attacker bypass the LoadMaster's security protections entirely and run elevated shell commands (ls, ps, cat, etc.) — enough to pull certificates, private keys, and other sensitive data off the load balancer.
Who can reach it
Fully remote and unauthenticated against the LoadMaster's management interface.
What to do
Software upgrade to LMOS 7.1.35.5 (LTS) or 7.2.41.2+ (mainline) per Kemp's mitigation article. Upgrade and reboot; if this LoadMaster fronts live inference traffic, fail over to a standby instance during the update. Also rotate any certificates/keys that were on the device, since the bug allowed reading them.
References
Related entries
- Slurm (slurmdbd, sacctmgr archive load): A second SQL injection path into SlurmDBD, this one through the 'sacctmgrCVE-2019-12838 · Slurm (slurmdbd, sacctmgr archive load)Critical
- HTCondor (condor_startd, condor_schedd, condor_shadow): One CVE covering four separate authentication failures theCVE-2019-18823 · HTCondor (condor_startd, condor_schedd, condor_shadow)Critical
- Lustre ptlrpc module (server-side client packet validation): A Lustre client can send a crafted RPC that overflows aCVE-2019-20427 · Lustre ptlrpc module (server-side client packet validation)Critical
- NetApp ONTAP Select Deploy administration utility (HTTP service): An unauthenticated attacker performs administrativeCVE-2019-5504 · NetApp ONTAP Select Deploy administration utility (HTTP service)Critical
- NetApp ONTAP Select Deploy administration utility (credential transport): Deploy sends its credentials in plaintext, soCVE-2019-5505 · NetApp ONTAP Select Deploy administration utility (credential transport)Critical
- NetApp ONTAP Select Deploy administration utility (code injection): An unauthenticated remote attacker injects code andCVE-2019-5509 · NetApp ONTAP Select Deploy administration utility (code injection)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.