CVE-2021-32085
- EPSS 0.21%
- Veröffentlicht 27.07.2026 22:16:57
- Zuletzt bearbeitet 03.08.2026 14:31:07
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attac...
CVE-2021-32086
- EPSS 0.1%
- Veröffentlicht 27.07.2026 22:16:57
- Zuletzt bearbeitet 03.08.2026 14:30:59
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access t...
CVE-2021-32087
- EPSS 0.21%
- Veröffentlicht 27.07.2026 22:16:57
- Zuletzt bearbeitet 03.08.2026 14:31:17
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to triviall...
CVE-2021-32088
- EPSS 0.29%
- Veröffentlicht 27.07.2026 22:16:57
- Zuletzt bearbeitet 03.08.2026 14:30:47
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.
CVE-2021-32084
- EPSS 0.15%
- Veröffentlicht 27.07.2026 22:16:56
- Zuletzt bearbeitet 03.08.2026 14:31:11
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the...
CVE-2023-33254
- EPSS 3.21%
- Veröffentlicht 21.05.2023 22:15:15
- Zuletzt bearbeitet 31.01.2025 16:15:30
There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a higher privilege level on the Active Directory domain. To exploit this, an authenticated attacker edits t...