8.8
CVE-2021-32085
- EPSS 0.29%
- Veröffentlicht 27.07.2026 22:16:57
- Zuletzt bearbeitet 03.08.2026 14:31:07
- CVE-Watchlists
- Unerledigt
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the MySQL databases. Sensitive information is stored in the database, such as privileged credentials for other systems.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Quest ≫ Kace Systems Management Appliance Version11.0.273
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.216 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
https://support.quest.com/download-product-select
https://support.quest.com/kace-systems-management-appliance/kb/4293505/quest-response-to-criticalstart-vulnerability-report