CVE-2021-32088
- EPSS 0.29%
- Veröffentlicht 27.07.2026 22:16:57
- Zuletzt bearbeitet 03.08.2026 14:30:47
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.
CVE-2021-32087
- EPSS 0.21%
- Veröffentlicht 27.07.2026 22:16:57
- Zuletzt bearbeitet 03.08.2026 14:31:17
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to triviall...
CVE-2021-32086
- EPSS 0.1%
- Veröffentlicht 27.07.2026 22:16:57
- Zuletzt bearbeitet 03.08.2026 14:30:59
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access t...
CVE-2021-32085
- EPSS 0.21%
- Veröffentlicht 27.07.2026 22:16:57
- Zuletzt bearbeitet 03.08.2026 14:31:07
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attac...
CVE-2021-32084
- EPSS 0.15%
- Veröffentlicht 27.07.2026 22:16:56
- Zuletzt bearbeitet 03.08.2026 14:31:11
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the...
CVE-2025-26850
- EPSS 0.16%
- Veröffentlicht 04.07.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.
CVE-2025-32978
- EPSS 0.91%
- Veröffentlicht 24.06.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to replace system licenses throug...
CVE-2025-32977
- EPSS 0.41%
- Veröffentlicht 24.06.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to upload backup files to the sys...
CVE-2025-32976
- EPSS 0.81%
- Veröffentlicht 24.06.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains a logic flaw in its two-factor authentication impleme...
- EPSS 2.42%
- Veröffentlicht 24.06.2025 00:00:00
- Zuletzt bearbeitet 21.04.2026 14:09:39
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows at...