{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2018-11138/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2018-11138/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2018-11138/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2018-11138/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2018-11138/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2018-11138"},"sightings":{"href":"/api/v1/sightings/cve-2018-11138"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.91778,"kev":true,"percentile":0.99812},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2018/CVE-2018-11138.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2018-11138\n\ninfo:\n  name: Quest KACE System Management Appliance 8.0.318 - Remote Code Execution\n  author: ritikchaddha\n  severity: critical\n  description: |\n    The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.\n  impact: |\n    An attacker can execute arbitrary commands on the affected system, potentially leading to complete system compromise, data theft, or further network exploitation.\n  remediation: |\n    Upgrade to a patched version of Quest KACE System Management Appliance or apply the necessary security patches provided by Quest Software.\n  reference:\n    - https://www.coresecurity.com/advisories/quest-kace-system-management-appliance-multiple-vulnerabilities\n    - https://www.exploit-db.com/exploits/44950/\n    - https://nvd.nist.gov/vuln/detail/CVE-2018-11138\n    - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11138\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2018-11138\n    cwe-id: CWE-78\n    epss-score: 0.91778\n    epss-percentile: 0.99812\n    cpe: cpe:2.3:a:quest:kace_system_management_appliance:8.0.318:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 2\n    vendor: quest\n    product: kace_system_management_appliance\n    fofa-query: icon_hash=\"-463230636\"\n  tags: cve,cve2018,quest,kace,rce,kev,passive,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}\"\n\n    host-redirects: true\n    matchers:\n      - type: dsl\n        dsl:\n          - 'contains_any(tolower(body), \"kace\", \"quest\")'\n          - 'compare_versions(detected_version, \"8.0.318\")'\n        condition: and\n\n    extractors:\n      - type: regex\n        part: body\n        name: detected_version\n        group: 1\n        regex:\n          - '\\?build=([0-9.]+)'\n# digest: 4b0a00483046022100de18d24af571000134b22acb02cd03439a5c103b4e247d7d5340fe88ec7cd0b6022100aaa65b8846033628a1a63b9319e940cffa5ee57d268adef47d91e1e079d2d2a6:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2018-11138"}