Skip to main content

KACE System Management Appliance vulnerabilities

1 published alerts for Quest KACE System Management Appliance.

Actively exploited (KEV)Ransomware

CVE-2018-11138

Quest KACE System Management Appliance Remote Command Execution Vulnerability

Quest KACE System Management Appliance is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-11138). The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.