CVE-2018-12335: High severity quest kace systems management appliance vulnerability
Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access and manipulate security relevant configurations, via unrestricted database access during Easy Enrollment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12335?
CVE-2018-12335 is classified as a high severity vulnerability due to its potential for unauthorized access and manipulation of security configurations.
How do I fix CVE-2018-12335?
To resolve CVE-2018-12335, upgrade the ECOS System Management Appliance to a version that addresses this access control issue.
What are the risks associated with CVE-2018-12335?
The risks associated with CVE-2018-12335 include compromised authentication keys and the ability to manipulate security-relevant configurations.
Who is affected by CVE-2018-12335?
CVE-2018-12335 affects users of ECOS System Management Appliance version 5.2.68.
What does CVE-2018-12335 exploit?
CVE-2018-12335 exploits incorrect access control during the Easy Enrollment process, allowing unrestricted database access.