QID 730863
Date Published: 2023-08-02
QID 730863: KACE Systems Management Appliance Cross-Site Scripting (XSS) Vulnerability
The KACE Systems Management Appliance provides your growing organization with comprehensive management of network-connected devices, including servers, PCs, Macs, Chromebooks, tablets, printers, storage, networking gear and the Internet of Things (IoT). KACE can fulfill all of your organization's systems management needs, from initial deployment to ongoing management and retirement.
Affected Versions:
Quest KACE System Management Appliance 12.0,12.1
QID Detection Logic(Unauthenticated):
It checks for vulnerable version of Quest KACE System Management Appliance.
An XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote injection of arbitrary web script or HTML.
Solution
Vendor has released the patch to address the reported vulnerabilities. For more details: KACE Systems Management Appliance
Vendor References
- KACE Systems Management Appliance -
support.quest.com/kb/4368602/quest-response-to-kace-sma-vulnerability-cve-2022-38220
CVEs related to QID 730863
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| KACE Systems Management Appliance |
|