VendorsQuestkace_systems_management_applianceany version
Vulnerabilities

Quest KACE Systems Management Appliance any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2025-32975
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.
Published 2025-06-24 · Analyzed
10.0KEVEPSS 0.025
CVE-2022-29807
A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via download_agent_installer.php.
Published 2022-08-02 · Modified
9.8EPSS 0.013
CVE-2022-30285
In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials.
Published 2022-08-02 · Modified
9.8EPSS 0.005
CVE-2018-5406
The Quest Kace K1000 Appliance misconfigures the Cross-Origin Resource Sharing (CORS) mechanism.
Published 2019-06-03 · Modified
9.31 PoCEPSS 0.122
CVE-2019-10973
Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveraging functions of the troubleshooting tools located in the administrator user interface.
Published 2019-07-08 · Modified
9.0EPSS 0.024
CVE-2022-29808
In Quest KACE Systems Management Appliance (SMA) through 12.0, predictable token generation occurs when appliance linking is enabled.
Published 2022-08-02 · Modified
7.5EPSS 0.007
CVE-2018-5404
The Quest Kace K1000 Appliance is vulnerable to multiple Blind SQL Injections.
Published 2019-06-03 · Modified
6.51 PoCEPSS 0.038
CVE-2019-11604
An issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbot_service_notsoap.php is vulnerable to unauthenticated reflected XSS when user-supplied input to the METHOD GET parameter is processed by the web application. Since the application does not properly validate and sanitize this parameter, it is possible to place arbitrary script code into the context of the same page.
Published 2019-05-24 · Modified
6.1EPSS 0.018
CVE-2022-38220
An XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote injection of arbitrary web script or HTML.
Published 2023-02-28 · Modified
6.1EPSS 0.007
CVE-2018-5405
The Quest Kace K1000 Appliance is vulnerable to JavaScript injection.
Published 2019-06-03 · Modified
5.41 PoCEPSS 0.037