Record summary

CVE-2019-20504 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 29, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALDell KACE Systems Management Appliance (K1000) 6.4.120756 - Remote Code ExecutionCVSS 9.8

service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.

Impact

Unauthenticated attackers can execute arbitrary system commands via shell metacharacters, leading to complete server compromise and access to all managed systems.

Remediation

Upgrade to KACE K1000 version 6.4 SP3 (6.4.120822) or later.

WeaknessesCWE-78
AuthorsDhiyaneshDk
Template tagscvecve2019k1000kacercevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:quest:kace_systems_management:*:*:*:*:*:*:*:*
Shodan: html:"K1000 Logo"

Source: ProjectDiscovery

References

2