CVE-2019-10973: Input Validation
Published Jul 8, 2019
·Updated
Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveraging functions of the troubleshooting tools located in the administrator user interface.
Affected Software
3 affected components
Quest KACE Systems Management Appliance>=8.0.0<=8.0.320
Quest KACE Systems Management Appliance>=8.1.0<=8.1.108
Quest KACE Systems Management Appliance>=9.0.0<=9.0.270
Remediation
Patch Available
Event History
Jul 8, 2019
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2019-10973.
2
What is the affected software?
The affected software is Quest KACE Systems Management Appliance versions prior to 8.0.x, 8.1.x, and 9.0.x.
3
What is the severity of CVE-2019-10973?
The severity of CVE-2019-10973 is critical with a CVSS score of 7.2.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-20.
5
How can I fix the vulnerability in Quest KACE Systems Management Appliance?
To fix the vulnerability, update Quest KACE Systems Management Appliance to version 8.0.x, 8.1.x, or 9.0.x.