CVE-2025-32975
CRITICAL KEVQuest KACE SMA <14.1.101 - Auth Bypass
Title source: llmDescription
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.
References (5)
Scores
CVSS v3
10.0
EPSS
0.4650
EPSS Percentile
97.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CISA KEV
2026-04-20
VulnCheck KEV
2026-03-19
ENISA EUVD
EUVD-2025-19028
CWE
CWE-287
Status
published
Products (1)
quest/kace_systems_management_appliance
13.0 - 13.0.385
Published
Jun 24, 2025
KEV Added
Apr 20, 2026
Tracked Since
Feb 18, 2026