VulnerabilityModified
CVE-2019-10973
Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveraging functions of the troubleshooting tools located in the administrator user interface.
HIGH 7.2EPSS 2.42%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveraging functions of the troubleshooting tools located in the administrator user interface.
- CVSS 3.0
- 7.2 HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.42% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- quest/kace systems management appliance
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/109001Third Party Advisory, VDB Entry
- https://www.us-cert.gov/ics/advisories/icsa-19-183-02Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/109001Third Party Advisory, VDB Entry
- https://www.us-cert.gov/ics/advisories/icsa-19-183-02Patch, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.