CVE-2018-12338: Critical severity quest kace systems management appliance vulnerability
Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confidential information and manipulate security relevant configurations via remote root SSH access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12338?
The severity of CVE-2018-12338 is classified as critical due to the potential for remote root SSH access and manipulation of security configurations.
How do I fix CVE-2018-12338?
Fixing CVE-2018-12338 involves updating the ECOS System Management Appliance to a patched version that resolves the undocumented factory backdoor.
What type of access does CVE-2018-12338 provide?
CVE-2018-12338 provides unauthorized remote root SSH access to the ECOS System Management Appliance.
What is the impact of CVE-2018-12338?
The impact of CVE-2018-12338 includes the potential extraction of confidential information and the ability to manipulate security settings.
Which version of the ECOS System Management Appliance is affected by CVE-2018-12338?
CVE-2018-12338 specifically affects version 5.2.68 of the ECOS System Management Appliance.