Quest Vulnerabilities and Affected Products
Vulnerabilities associated with kace_systems_management.
Products
Clear product- Quest NetVault Backup24 vulnerabilities
- NetVault Backup10 vulnerabilities
- kace_systems_management_appliance3 vulnerabilities
- Coexistence Manager for Notes1 vulnerability
- Foglight Evolve1 vulnerability
- KACE System Management Appliance1 vulnerability
- KACE Systems Management Appliance1 vulnerability
- KACE Systems Management Appliance (SMA)1 vulnerability
- kace_systems_management1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-20504CRITICAL | quest kace_systems_management Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter. | CVSS9.8v3.1 | EPSS9.55% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |