First published: Tue Aug 02 2022(Updated: )
In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quest KACE Systems Management Appliance | <12.1.168 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30285 is a vulnerability in Quest KACE Systems Management Appliance (SMA) through version 12.0, which allows for hash collision during authentication.
CVE-2022-30285 allows for authentication with invalid credentials in Quest KACE Systems Management Appliance through version 12.0.
CVE-2022-30285 has a severity level of critical.
To fix CVE-2022-30285, it is recommended to update Quest KACE Systems Management Appliance to version 12.1.168 or later.
You can find more information about CVE-2022-30285 on the Quest support website at https://support.quest.com/kace-systems-management-appliance/kb/338232/quest-response-to-kace-sma-vulnerabilities-cve-2022-30285.