Quest

Kace Systems Deployment Appliance

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 27.07.2026 22:16:57
  • Zuletzt bearbeitet 03.08.2026 14:31:07

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attac...

  • EPSS 0.1%
  • Veröffentlicht 27.07.2026 22:16:57
  • Zuletzt bearbeitet 03.08.2026 14:30:59

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access t...

  • EPSS 0.21%
  • Veröffentlicht 27.07.2026 22:16:57
  • Zuletzt bearbeitet 03.08.2026 14:31:17

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to triviall...

  • EPSS 0.29%
  • Veröffentlicht 27.07.2026 22:16:57
  • Zuletzt bearbeitet 03.08.2026 14:30:47

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.

  • EPSS 0.15%
  • Veröffentlicht 27.07.2026 22:16:56
  • Zuletzt bearbeitet 03.08.2026 14:31:11

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the...

Exploit
  • EPSS 3.21%
  • Veröffentlicht 21.05.2023 22:15:15
  • Zuletzt bearbeitet 31.01.2025 16:15:30

There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a higher privilege level on the Active Directory domain. To exploit this, an authenticated attacker edits t...