Description
An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the download_agent.php endpoint. An attacker can upload arbitrary PHP files to a temporary web-accessible directory, which are later executed through inclusion in backend code that loads files under attacker-controlled paths.
Published: 2025-08-05
Score: 9.3 Critical
EPSS: 56.5% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2014-9817 An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the download_agent.php endpoint. An attacker can upload arbitrary PHP files to a temporary web-accessible directory, which are later executed through inclusion in backend code that loads files under attacker-controlled paths.
History

Fri, 21 Nov 2025 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell kace K1000 Systems Management Appliance Software
CPEs cpe:2.3:a:dell:kace_k1000_systems_management_appliance_software:*:*:*:*:*:*:*:*
Vendors & Products Dell
Dell kace K1000 Systems Management Appliance Software

Thu, 07 Aug 2025 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Quest
Quest kace Systems Management Appliance
Vendors & Products Quest
Quest kace Systems Management Appliance

Wed, 06 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 05 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Description An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the download_agent.php endpoint. An attacker can upload arbitrary PHP files to a temporary web-accessible directory, which are later executed through inclusion in backend code that loads files under attacker-controlled paths.
Title Dell/Quest KACE K1000 Unauthenticated File Upload RCE
Weaknesses CWE-306
CWE-434
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Dell Kace K1000 Systems Management Appliance Software
Quest Kace Systems Management Appliance
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-05-14T02:06:24.124Z

Reserved: 2025-07-23T21:08:10.909Z

Link: CVE-2014-125113

cve-icon Vulnrichment

Updated: 2025-08-06T13:46:03.520Z

cve-icon NVD

Status : Deferred

Published: 2025-08-05T20:15:36.000

Modified: 2026-04-15T00:35:42.020

Link: CVE-2014-125113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-06T15:12:50Z

Weaknesses