unauthenticated-rce

1 article
Sort: New Top Best
clear filter
0

An unauthenticated remote code execution vulnerability in Dell KACE K1000 Systems Management Appliance (version 6.3.113397 and earlier) exists in the /service/krashrpt.php endpoint, which fails to properly sanitize the kuid and name parameters before passing them to shell commands, allowing arbitrary code execution on the appliance and potentially all managed client endpoints. The vulnerability was silently patched by Dell in version 6.4 SP3 (6.4.120822) under bug ID K1-18652.

CVE-2019-XXXX K1-18652 Dell KACE K1000 Quest Software Inc Julien Ahrens Dropbox H1-3120
rcesecurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details