CVE-2014-125113: Dell/quest KACE k1000 Systems Management Appliance
Critical severity, CVSS 9.3. EPSS: 1.5% chance of exploitation in the next 30 days.
An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the download_agent.php endpoint. An attacker can upload arbitrary PHP files to a temporary web-accessible directory, which are later executed through inclusion in backend code that loads files under attacker-controlled paths.
Affected products
- Dell/quest KACE k1000 Systems Management Appliance: from 5.0, up to and including 5.3; from 5.4, before 5.4.76849 (fixed in 5.4.76849); from 5.5, before 5.5.90547 (fixed in 5.5.90547)
Published 2025-08-05. Last modified 2026-06-17.