PatchSiren

Quest CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Quest CVE published 2026-07-27

CVE-2021-32088

CVE-2021-32088 is a critical vulnerability in Quest KACE Systems Management Appliance 11.0.273. The issue allows for the bypass of rate-limiting features in certain API endpoints by removing the kboxid cookie, potentially enabling brute-force attacks. This vulnerability has a CVSS score of 9.8, indicating a high severity level. Organizations using Quest KACE Systems Management Appliance 11.0.273 should pr [truncated]

HIGH Quest CVE published 2026-07-27

CVE-2021-32087

CVE-2021-32087 is a high-severity vulnerability in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. The appliance installs with default user credentials for the kbftp account, which has a publicly known password of getbxf. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups storing sensitive information such as privileged crede [truncated]

CRITICAL Quest CVE published 2026-07-27

CVE-2021-32086

CVE-2021-32086 is a critical vulnerability in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. The appliance uses a hardcoded symmetric encryption key for secrets in MySQL databases, which is not unique to each installation. This oversight allows an attacker with access to the MySQL server or backup files to decrypt these secrets, potentially leading to privilege escalation within KACE or access to [truncated]

HIGH Quest CVE published 2026-07-27

CVE-2021-32085

CVE-2021-32085 is a high-severity vulnerability in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. The vulnerability allows remote attackers to gain privileged access to the MySQL databases due to default user credentials. The report and R1 MySQL accounts have a publicly known password of 'box747', which can be used to access sensitive information stored in the database. Organizations should revie [truncated]

Known exploited Quest CVE published 2026-04-20

CVE-2025-32975

CVE-2025-32975 is an improper authentication vulnerability in Quest KACE Systems Management Appliance (SMA) that CISA added to the Known Exploited Vulnerabilities catalog on 2026-04-20. The KEV listing means defenders should treat it as an urgent remediation item, even though the supplied public corpus does not include affected versions, impact depth, or exploit mechanics. CISA’s guidance is to apply vend [truncated]

Known exploited Quest CVE published 2022-03-25

CVE-2018-11138

CVE-2018-11138 is a Quest KACE System Management Appliance remote command execution issue that CISA has listed in its Known Exploited Vulnerabilities catalog. The KEV record flags known exploitation and indicates known ransomware campaign use, so this should be treated as an urgent remediation item rather than a routine patch. CISA’s guidance for this entry is to apply updates per the vendor’s instructions.