CVE-2018-11138: Quest KACE System Management Appliance Remote Command Execution Vulnerability
The '/common/downloadagentinstaller.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
Other sources
The '/common/downloadagentinstaller.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the appliance/web server to disable anonymous access to the /common/download_agent_installer.php endpoint so that only authenticated users can access it, or remove/disable that endpoint if not required.
Quest KACE Systems Management Appliance anonymous access to /common/download_agent_installer.php = disabled (require authentication) - Compensating control
Block or restrict network access to the /common/download_agent_installer.php path at the perimeter (firewall, WAF, or reverse proxy) so that only trusted management IPs or internal networks can reach it.
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11138?
CVE-2018-11138 has a high severity rating due to its potential for remote command execution.
How do I fix CVE-2018-11138?
To fix CVE-2018-11138, it is recommended to update to a patched version of the Quest KACE System Management Appliance.
Who is affected by CVE-2018-11138?
CVE-2018-11138 affects users of the Quest KACE System Management Appliance version 8.0.318.
What type of vulnerability is CVE-2018-11138?
CVE-2018-11138 is classified as a remote code execution vulnerability.
Can CVE-2018-11138 be exploited by unauthenticated users?
Yes, CVE-2018-11138 can be exploited by unauthenticated users due to the accessible script.