« Volver al listado

Quest

Quest Kace System Management Appliance: vulnerabilidades y CVE

Quest Kace System Management Appliance tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses0
Críticas4
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2018-11138Crítica (9.8)92%⚠ Explotación activa31 may 2018
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2018-11142Media (5.5)0.42%—31 may 2018
The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management Appliance 8.0.318 are accessible only from localhost. This restriction can be bypassed by modifying…
CVE-2018-11141Crítica (9.8)2.0%—31 may 2018
The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via…
CVE-2018-11140Crítica (9.8)1.4%—31 may 2018
The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, an error-based type).
CVE-2018-11139Alta (8.8)43%—31 may 2018
The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This…
CVE-2018-11138Crítica (9.8)92%⚠ Explotación activa31 may 2018
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
CVE-2018-11137Media (6.5)6.5%—31 may 2018
The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be abused to read arbitrary files with 'www' privileges via Directory Traversal. No…
CVE-2018-11136Crítica (9.8)1.4%—31 may 2018
The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, a blind time-based…
CVE-2018-11135Alta (8.8)2.1%—31 may 2018
The script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users to conduct PHP object injection attacks.
CVE-2018-11134Alta (8.8)3.0%—31 may 2018
In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of…
CVE-2018-11133Media (6.1)8.7%—31 may 2018
The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting.
CVE-2018-11132Alta (8.8)18%—31 may 2018
In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a set of commands to be…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter1
  2. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Quest