7.5
CVSSv2

CVE-2019-20504

Published: 09/03/2020 Updated: 24/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

service/krashrpt.php in Quest KACE K1000 Systems Management Appliance prior to 6.4 SP3 (6.4.120822) allows a remote malicious user to execute code via shell metacharacters in the kuid parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

quest kace systems management

Github Repositories

The API for CVEs and USNs data.

ubuntucom security API API functions under ubuntucom for querying CVEs and security notices Local development The simplest way to run the API locally is using the dotrun snap: dotrun # In the root of the project folder This will start a database, import some sample data and run the server Exiting the server with ctrl + c should autom

The API for CVEs and USNs data.

ubuntucom security API API functions under ubuntucom for querying CVEs and security notices Local development The simplest way to run the API locally is using the dotrun snap: dotrun # In the root of the project folder This will start a database, import some sample data and run the server Exiting the server with ctrl + c should autom

The API for CVEs and USNs data.

ubuntucom security API API functions under ubuntucom for querying CVEs and security notices Local development The simplest way to run the API locally is using the dotrun snap: dotrun # In the root of the project folder This will start a database, import some sample data and run the server Exiting the server with ctrl + c should autom

The API for CVEs and USNs data.

ubuntucom security API API functions under ubuntucom for querying CVEs and security notices Local development The simplest way to run the API locally is using the dotrun snap: dotrun # In the root of the project folder This will start a database, import some sample data and run the server Exiting the server with ctrl + c should autom