CVE-2019-20504
quest kace_systems_management Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2019-20504 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 29, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
kace_systems_managementBrowse quest / kace_systems_management | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALDell KACE Systems Management Appliance (K1000) 6.4.120756 - Remote Code ExecutionCVSS 9.8
service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.
Impact
Unauthenticated attackers can execute arbitrary system commands via shell metacharacters, leading to complete server compromise and access to all managed systems.
Remediation
Upgrade to KACE K1000 version 6.4 SP3 (6.4.120822) or later.
Source: ProjectDiscovery