CVE-2014-1671 EXPLOIT
6.5
MEDIUM · CVSS 2.0 · EPSS 1.9% (pctl 80)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the macAddress element in a (1) getUploadPath or (2) getKBot SOAP request to service/kbot_service.php; the ID parameter to (3) userui/advisory_detail.php or (4) userui/ticket.php; and the (5) ORDER[] parameter to userui/ticket_list.php.
Scoring
| CVSS | 6.5 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
| EPSS | 1.95% — more likely to be exploited than 80% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-01-26 |
| Last modified | 2026-06-17 |
Affected (5)
| Vendor | Product |
|---|---|
| dell | kace k1000 systems management appliance |
| dell | kace k1000 systems management appliance software |
| dell | kace k1000 systems management virtual appliance |
| dell | kace k1100s systems management appliance |
| dell | kace k1200s systems management appliance |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Dell Kace 1000 Systems Management Appliance DS-2014-001 - Multiple SQL Injections | 2014-01-13 |
References
- http://secunia.com/advisories/56396
- http://www.baesystemsdetica.com.au/Research/Advisories/Dell-KACE-K1000-SQL-Injection-%28DS-2014-001%29
- http://www.securityfocus.com/bid/65029
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90592
- http://secunia.com/advisories/56396
- http://www.baesystemsdetica.com.au/Research/Advisories/Dell-KACE-K1000-SQL-Injection-%28DS-2014-001%29
- http://www.securityfocus.com/bid/65029
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90592
→ the Explorer · watch your stack · NVD