PatchSiren cyber security CVE debrief
CVE-2021-32085 Quest CVE debrief
CVE-2021-32085 is a high-severity vulnerability in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. The vulnerability allows remote attackers to gain privileged access to the MySQL databases due to default user credentials. The report and R1 MySQL accounts have a publicly known password of 'box747', which can be used to access sensitive information stored in the database. Organizations should review their deployments, assess potential impact, and prioritize remediation efforts. This vulnerability can lead to unauthorized access and potential data breaches if not addressed promptly.
- Vendor
- Quest
- Product
- KACE Systems Deployment Appliance (SMA)
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-08-03
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-08-03
Who should care
Organizations using Quest KACE Systems Management Appliance 11.0.273, administrators and users of the affected systems, and security teams responsible for vulnerability management should prioritize immediate action to secure their systems. This includes reviewing and updating sensitive information stored in the database, implementing additional security measures to prevent unauthorized access, and ensuring that default credentials are changed. Security teams should also review monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Additionally, operators and platform administrators should be aware of the potential impact and take necessary steps to mitigate the vulnerability. Vulnerability management teams should assess the risk and prioritize remediation efforts based on the severity of the vulnerability and the potential impact on the organization. Asset owners and security teams should work together to ensure that affected systems are identified and remediated promptly. Change management processes should be followed to ensure that updates are properly tested and deployed. IT security teams should also review and update incident response plans to address potential breaches related to this vulnerability. Compliance teams may need to assess the impact on regulatory requirements and ensure that necessary controls are in place. Communication plans should be developed to inform stakeholders about the vulnerability and remediation efforts. Finally, security awareness training may be necessary to educate users about the risks associated with this vulnerability and the importance of prompt remediation. Business continuity plans should be reviewed to ensure that they account for potential disruptions related to remediation efforts. Supply chain risk management teams should assess the impact on third-party vendors and suppliers. Audit and risk management teams should review the vulnerability and associated risks to ensure that they are properly addressed. The CISO and other executive stakeholders should be informed about the vulnerability and its risk
Technical summary
CVE-2021-32085 is a high-severity vulnerability in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. The vulnerability allows remote attackers to gain privileged access to the MySQL databases due to default user credentials. The report and R1 MySQL accounts have a publicly known password of 'box747', which can be used to access sensitive information stored in the database, such as privileged credentials for other systems. This vulnerability can lead to unauthorized access, data breaches, and potential lateral movement within the network.
Defensive priority
Organizations using Quest KACE Systems Management Appliance 11.0.273 should prioritize immediate action to secure their systems, focusing on changing default credentials and ensuring sensitive information is properly protected.
Recommended defensive actions
- Change default credentials for report and R1 MySQL accounts
- Review and update sensitive information stored in the database
- Implement additional security measures to prevent unauthorized access
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record indicates that Quest KACE Systems Deployment Appliance (SMA) 11.0.273 installs with default user credentials, specifically the report and R1 MySQL accounts having a password of 'box747', which is publicly known. Sensitive information, such as privileged credentials for other systems, is stored in the database.
Official resources
-
CVE-2021-32085 CVE record
CVE.org
-
CVE-2021-32085 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
[email protected] - Product
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T22:16:57.500Z and has not been modified since then.