Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains a logic flaw in its two-factor authentication implementation that allows authenticated users to bypass TOTP-based 2FA requirements. The vulnerability exists in the 2FA validation process and can be exploited to gain elevated access.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Quest KACE Systems Management Appliance 安全漏洞
Vulnerability Description
Quest Software Quest KACE Systems Management Appliance是美国Quest Software公司的一款IT资产管理设备。 Quest KACE Systems Management Appliance存在安全漏洞,该漏洞源于双因素认证实现存在逻辑缺陷,可能导致绕过TOTP认证要求。以下版本受到影响:13.0.385之前版本、13.1.81之前版本、13.2.183之前版本、14.0.341之前版本和14.1.101之前版本。
CVSS Information
N/A
Vulnerability Type
N/A