PatchSiren cyber security CVE debrief
CVE-2021-32087 Quest CVE debrief
CVE-2021-32087 is a high-severity vulnerability in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. The appliance installs with default user credentials for the kbftp account, which has a publicly known password of getbxf. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups storing sensitive information such as privileged credentials for other systems. Affected organizations should prioritize immediate action to secure their systems, focusing on changing default credentials and ensuring FTP service security. The CVE record was published on 2026-07-27T22:16:57.723Z and has not been modified since then. Evidence is based on official CVE and NVD records.
- Vendor
- Quest
- Product
- KACE Systems Management Appliance
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-08-03
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-08-03
Who should care
IT administrators and security teams responsible for Quest KACE Systems Management Appliance 11.0.273, especially those with systems exposed to the internet or untrusted networks, should be aware of this vulnerability and take immediate action to secure their systems. This includes reviewing and updating their current security configurations, ensuring FTP service security, and applying vendor patches or updates if available.
Technical summary
CVE-2021-32087 is a high-severity vulnerability in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. The appliance installs with default user credentials for the kbftp account, which has a publicly known password of getbxf. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups storing sensitive information such as privileged credentials for other systems. Organizations using Quest KACE Systems Management Appliance 11.0.273 should prioritize immediate action to secure their systems, focusing on changing default credentials and ensuring FTP service security. The vulnerability allows attackers to gain access to sensitive information, including privileged credentials for other systems, which can lead to further exploitation.
Defensive priority
Organizations using Quest KACE Systems Management Appliance 11.0.273 should prioritize immediate action to secure their systems, focusing on changing default credentials and ensuring FTP service security.
Recommended defensive actions
- Change default kbftp account password immediately
- Restrict access to FTP service interface
- Review and secure MySQL backups
- Monitor for suspicious activity
- Apply vendor patches or updates if available
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE-2021-32087 issue involves Quest KACE Systems Deployment Appliance (SMA) 11.0.273, which installs with default user credentials. The kbftp account has a publicly known password of getbxf, allowing remote attackers to gain privileged access to the FTP service interface containing MySQL backups with sensitive information such as privileged credentials for other systems. Evidence is based on official CVE and NVD records.
Official resources
-
CVE-2021-32087 CVE record
CVE.org
-
CVE-2021-32087 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
[email protected] - Product
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T22:16:57.723Z and has not been modified since then.