QID 730879

Date Published: 2023-10-05

QID 730879: KACE Systems Management Appliance SQL Injection Vulnerability

The KACE Systems Management Appliance provides your growing organization with comprehensive management of network-connected devices, including servers, PCs, Macs, Chromebooks, tablets, printers, storage, networking gear and the Internet of Things (IoT). KACE can fulfill all of your organization's systems management needs, from initial deployment to ongoing management and retirement.
CVE-2022-29807: A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution.

Affected Versions:
KACE Systems Management Appliance prior to 12.1.168

QID Detection Logic(Unauthenticated):

It checks for vulnerable version of Quest KACE System Management Appliance.
Note: detection made practice as unable to check for the hotfix

A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) that can allow for remote code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released the patch to address the reported vulnerabilities. For more details: KACE Systems Management Appliance

    CVEs related to QID 730879

    Software Advisories
    Advisory ID Software Component Link
    KACE Systems Management Appliance URL Logo support.quest.com/kace-systems-management-appliance/kb/4258792/quest-response-to-kace-sma-vulnerabilities-cve-2022-29807