CVE-2018-11138: Quest KACE System Management Appliance Remote Command Execution Vulnerability
The '/common/downloadagentinstaller.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
Other sources
The '/common/downloadagentinstaller.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11138?
CVE-2018-11138 has a high severity rating due to its potential for remote command execution.
How do I fix CVE-2018-11138?
To fix CVE-2018-11138, it is recommended to update to a patched version of the Quest KACE System Management Appliance.
Who is affected by CVE-2018-11138?
CVE-2018-11138 affects users of the Quest KACE System Management Appliance version 8.0.318.
What type of vulnerability is CVE-2018-11138?
CVE-2018-11138 is classified as a remote code execution vulnerability.
Can CVE-2018-11138 be exploited by unauthenticated users?
Yes, CVE-2018-11138 can be exploited by unauthenticated users due to the accessible script.