9.8
CVE-2021-32086
- EPSS 0.19%
- Veröffentlicht 27.07.2026 22:16:57
- Zuletzt bearbeitet 03.08.2026 14:30:59
- CVE-Watchlists
- Unerledigt
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often, the decrypted secrets can be used to escalate privileges within KACE, or gain privileged access to unrelated systems or services.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Quest ≫ Kace Systems Management Appliance Version11.0.273
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.09 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-321 Use of Hard-coded Cryptographic Key
The product uses a hard-coded, unchangeable cryptographic key.
https://support.quest.com/download-product-select
https://support.quest.com/kace-systems-management-appliance/kb/4293505/quest-response-to-criticalstart-vulnerability-report