CVE-2022-30285: Weak Encryption
In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-30285?
CVE-2022-30285 is a vulnerability in Quest KACE Systems Management Appliance (SMA) through version 12.0, which allows for hash collision during authentication.
How does CVE-2022-30285 affect Quest KACE Systems Management Appliance?
CVE-2022-30285 allows for authentication with invalid credentials in Quest KACE Systems Management Appliance through version 12.0.
What is the severity level of CVE-2022-30285?
CVE-2022-30285 has a severity level of critical.
How can I fix CVE-2022-30285 in Quest KACE Systems Management Appliance?
To fix CVE-2022-30285, it is recommended to update Quest KACE Systems Management Appliance to version 12.1.168 or later.
Where can I find more information about CVE-2022-30285?
You can find more information about CVE-2022-30285 on the Quest support website at https://support.quest.com/kace-systems-management-appliance/kb/338232/quest-response-to-kace-sma-vulnerabilities-cve-2022-30285.