← לוח פגיעויות

CVE-2018-11138

קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Quest KACE System Management Appliance Remote Command Execution Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
92% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-78

מוצרים מושפעים

quest: kace system management appliance

קישורים