CVE-2025-32975

CRITICAL KEV

Quest KACE SMA <14.1.101 - Auth Bypass

Title source: llm

Description

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.

Scores

CVSS v3 10.0
EPSS 0.4650
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CISA KEV 2026-04-20
VulnCheck KEV 2026-03-19
ENISA EUVD EUVD-2025-19028
CWE
CWE-287
Status published
Products (1)
quest/kace_systems_management_appliance 13.0 - 13.0.385
Published Jun 24, 2025
KEV Added Apr 20, 2026
Tracked Since Feb 18, 2026