Zurück zur CVE-Übersicht
CVE-2018-11138
CRITICAL(9.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Risk Signal Score82/100 — KRITISCH
- CVSS 9.8 — Kritisch
- EPSS 92% — sehr wahrscheinlich ausgenutzt
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
92.1%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
CVE-2018-11138 betrifft das Skript '/common/download_agent_installer.php' in der Quest KACE System Management Appliance Version 8.0.318. Diese Schwachstelle ermöglicht es anonymen Benutzern, beliebige Befehle auf dem System auszuführen. Die Ausnutzung kann zu einer vollständigen Kompromittierung des betroffenen Systems führen.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
Betroffene Produkte
- cpe:2.3:a:quest:kace_system_management_appliance:8.0.318:*:*:*:*:*:*:*
Referenzen
- https://www.coresecurity.com/advisories/quest-kace-system-management-appliance-m...
- https://www.exploit-db.com/exploits/44950/
- https://www.coresecurity.com/advisories/quest-kace-system-management-appliance-m...
- https://www.exploit-db.com/exploits/44950/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-...