QID 730863

Date Published: 2023-08-02

QID 730863: KACE Systems Management Appliance Cross-Site Scripting (XSS) Vulnerability

The KACE Systems Management Appliance provides your growing organization with comprehensive management of network-connected devices, including servers, PCs, Macs, Chromebooks, tablets, printers, storage, networking gear and the Internet of Things (IoT). KACE can fulfill all of your organization's systems management needs, from initial deployment to ongoing management and retirement.

Affected Versions:

Quest KACE System Management Appliance 12.0,12.1

QID Detection Logic(Unauthenticated):

It checks for vulnerable version of Quest KACE System Management Appliance.

An XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote injection of arbitrary web script or HTML.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released the patch to address the reported vulnerabilities. For more details: KACE Systems Management Appliance

    CVEs related to QID 730863

    Software Advisories
    Advisory ID Software Component Link
    KACE Systems Management Appliance URL Logo support.quest.com/kb/4368602/quest-response-to-kace-sma-vulnerability-cve-2022-38220