CVE-2018-5406

HIGH

Quest Kace K1000 <9.0.270 - CSRF

Title source: llm
STIX 2.1

Description

The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS) mechanism. An unauthenticated, remote attacker could exploit this vulnerability to perform sensitive actions such as adding a new administrator account or changing the appliance’s settings. A malicious internal user could also gain administrator privileges of this appliance and use it to visit a malicious link that exploits this vulnerability. This could cause the application to perform sensitive actions such as adding a new administrator account or changing the appliance’s settings. An unauthenticated, remote attacker could add an administrator-level account or change the appliance's settings.

Exploits (1)

exploitdb WORKING POC VERIFIED
by SlidingWindow · textwebappsphp
https://www.exploit-db.com/exploits/46956

References (3)

Core 3
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://www.kb.cert.org/vuls/id/877837/

Scores

CVSS v3 8.8
EPSS 0.1623
EPSS Percentile 94.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (1)
quest/kace_systems_management_appliance_firmware < 9.0.270
Published Jun 03, 2019
Tracked Since Feb 18, 2026