VulnerabilityModified
CVE-2022-38220
An XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote injection of arbitrary web script or HTML.
MEDIUM 6.1EPSS 0.69%
Does this matter?
Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.
Description
An XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote injection of arbitrary web script or HTML.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- quest/kace systems management appliance
- Source
- cve@mitre.org
References
- https://support.quest.com/kb/339613Broken Link
- https://support.quest.com/kb/4368602/quest-response-to-kace-sma-vulnerability-cve-2022-38220Vendor Advisory
- https://support.quest.com/kb/339613Broken Link
- https://support.quest.com/kb/4368602/quest-response-to-kace-sma-vulnerability-cve-2022-38220Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.