← Vulnerability feed

Vulnerability record · CVE-2025-32975 · published 24 June 2025

CVE-2025-32975: Quest KACE SMA SSO authentication bypass allows admin takeover

Quest · Kace Systems Management Appliance

Quest KACE Systems Management Appliance contains an authentication bypass in its SSO authentication handling, letting attackers impersonate legitimate users without valid credentials. Because the appliance is used for endpoint management and patching, a bypass leading to full administrative takeover puts every managed device at risk.

10.0 CVSS 3.1 Critical CISA KEV since 20 Apr 2026 EPSS 2.5% · top 16.0% CWE-287 · Improper authentication
10.0CVSS 3.1 base score
2.5%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 10.0 unauthenticated network authentication bypass leading to full administrative takeover, with confirmed exploitation per CISA KEV.

What it is

Quest KACE Systems Management Appliance contains an authentication bypass in its SSO authentication handling, letting attackers impersonate legitimate users without valid credentials. Because the appliance is used for endpoint management and patching, a bypass leading to full administrative takeover puts every managed device at risk.

Impact

An unauthenticated attacker can impersonate users and achieve complete administrative control of the KACE SMA, enabling management-agent abuse, script or patch deployment, and access to managed endpoints and their data.

Attack surface

Reachable over the network via the SSO authentication handling mechanism, per the CVSS vector AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. The description does not specify which SSO endpoint or protocol is involved.

Exploitation

CVE-2025-32975 is listed in CISA KEV with a 2026-05-04 remediation due date, indicating known exploitation; EPSS 30-day probability is about 2.5 percent (83rd percentile). No ransomware campaign use is documented.

What to do

  • Upgrade to the fixed KACE SMA releases: 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5) or 14.1.101 (Patch 4), or later.
  • If patching is not immediately possible, follow the vendor's KB 4379499 mitigation guidance or restrict/disable SSO authentication until the appliance is updated.
  • Remove KACE SMA management interfaces from direct internet exposure; place them behind VPN or an access-controlled reverse proxy.
  • Audit and rotate credentials and API keys used by the appliance, and review local and SSO-linked accounts for unauthorized additions.
  • Apply CISA KEV required actions and BOD 22-01 guidance, including discontinuing use if mitigations are unavailable.

Detection

  • Review KACE SMA authentication and SSO logs for successful logins without a preceding credential or SSO assertion, and for logins from unexpected source IPs or user agents.
  • Monitor for new or modified administrative accounts, role changes, and unexpected script, patch or agent deployment tasks on the appliance.
  • Alert on outbound connections from the SMA to unusual destinations, which may indicate post-exploitation activity.
  • Correlate appliance audit logs with downstream endpoint management actions to spot unauthorized mass deployment or configuration changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-32975 to the Known Exploited Vulnerabilities catalog on 20 April 2026 as "Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 4 May 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-32975 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-32086Quest kace systems management appliance vulnerabilityAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in…EPSS 0.33%9.8CVE-2021-32088Quest kace systems management appliance vulnerabilityAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize …EPSS 0.52%9.8CVE-2021-32084Quest kace systems management appliance improper access control vulnerabilityAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or…EPSS 0.56%9.8CVE-2022-29807Quest kace systems management appliance sql injection vulnerabilityA SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via d…EPSS 1.4%9.8CVE-2022-30285Quest kace systems management appliance inadequate encryption strength vulnerabilityIn Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with…EPSS 0.55%9.8CVE-2019-12918Quest kace systems management appliance sql injection vulnerabilityQuest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and a…EPSS 1.1%9.8CVE-2017-12567Quest kace asset management appliance sql injection vulnerabilitySQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems Management Appliance 6.4.120822 through 7.2.101, and K1…EPSS 1.2%8.8CVE-2021-32085Quest kace systems management appliance hard-coded credentials vulnerabilityAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2025-32975), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.