PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-32087 Quest CVE debrief

CVE-2021-32087 is a high-severity vulnerability in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. The appliance installs with default user credentials for the kbftp account, which has a publicly known password of getbxf. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups storing sensitive information such as privileged credentials for other systems. Affected organizations should prioritize immediate action to secure their systems, focusing on changing default credentials and ensuring FTP service security. The CVE record was published on 2026-07-27T22:16:57.723Z and has not been modified since then. Evidence is based on official CVE and NVD records.

Vendor
Quest
Product
KACE Systems Management Appliance
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-08-03
Advisory published
2026-07-27
Advisory updated
2026-08-03

Who should care

IT administrators and security teams responsible for Quest KACE Systems Management Appliance 11.0.273, especially those with systems exposed to the internet or untrusted networks, should be aware of this vulnerability and take immediate action to secure their systems. This includes reviewing and updating their current security configurations, ensuring FTP service security, and applying vendor patches or updates if available.

Technical summary

CVE-2021-32087 is a high-severity vulnerability in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. The appliance installs with default user credentials for the kbftp account, which has a publicly known password of getbxf. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups storing sensitive information such as privileged credentials for other systems. Organizations using Quest KACE Systems Management Appliance 11.0.273 should prioritize immediate action to secure their systems, focusing on changing default credentials and ensuring FTP service security. The vulnerability allows attackers to gain access to sensitive information, including privileged credentials for other systems, which can lead to further exploitation.

Defensive priority

Organizations using Quest KACE Systems Management Appliance 11.0.273 should prioritize immediate action to secure their systems, focusing on changing default credentials and ensuring FTP service security.

Recommended defensive actions

  • Change default kbftp account password immediately
  • Restrict access to FTP service interface
  • Review and secure MySQL backups
  • Monitor for suspicious activity
  • Apply vendor patches or updates if available
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE-2021-32087 issue involves Quest KACE Systems Deployment Appliance (SMA) 11.0.273, which installs with default user credentials. The kbftp account has a publicly known password of getbxf, allowing remote attackers to gain privileged access to the FTP service interface containing MySQL backups with sensitive information such as privileged credentials for other systems. Evidence is based on official CVE and NVD records.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-32087 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-32087

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-32087 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-32087

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.