Progress Kemp LoadMaster Unauthenticated Command Injection via /access/set GET Parameters

Alerts on suspicious LoadMaster /access/set GET requests with enableapi/value=1 and anomalous Basic Authorization header content.

FreeReviewedSigma · High · v5
Category
webserver
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-03-20
Updated
2026-07-31

What it detects

This rule flags likely exploitation attempts against Progress Kemp LoadMaster by matching unauthenticated HTTP GET requests targeting the /access/set endpoint. It looks for specific query parameters (param=enableapi and value=1) combined with an Authorization header containing base64-encoded content that includes uncommon characters, which can indicate crafted payloads. Telemetry required includes webserver request method, requested URI stem, query string, and the Authorization header.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.