Rhino Security Labs

Strategic & Technical Blog

Vestaboard: Exploring Broken Access Controls and Privilege Escalation

Tyler Ramsbey
August 6, 2024

During research on the Vestaboard web platform, the Rhino research team identified three instances of Broken Access Controls.

Read-Access to other Vestaboards. 
Ability to update names of other users. 
Privilege escalation from Admin to…

CVE-2024-2389:
Command Injection Vulnerability
In Progress Flowmon

CVE-2024-2448:
Authenticated Command Injection
In Progress Kemp LoadMaster

CVE-2024-1212:
Unauthenticated Command Injection
In Progress Kemp LoadMaster

David Yesland

While researching the Progress Kemp LoadMaster load balancer we discovered an unauthenticated command injection in the administrator web interface of the appliance. This allowed full compromise of the LoadMaster if you could reach the…