PT-2025-26740 · Quest · Quest Kace System Management Appliance

Mohamed Mahmoudi

+1

·

Published

2025-06-24

·

Updated

2026-06-05

·

CVE-2025-32975

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quest KACE Systems Management Appliance (SMA) versions 13.0.x prior to 13.0.385 Quest KACE Systems Management Appliance (SMA) versions 13.1.x prior to 13.1.81 Quest KACE Systems Management Appliance (SMA) versions 13.2.x prior to 13.2.183 Quest KACE Systems Management Appliance (SMA) versions 14.0.x prior to 14.0.341 (Patch 5) Quest KACE Systems Management Appliance (SMA) versions 14.1.x prior to 14.1.101 (Patch 4)
Description An authentication bypass issue exists in the SSO authentication handling mechanism, allowing remote attackers to impersonate legitimate users without valid credentials, which can lead to complete administrative takeover. Other identified flaws include errors in cryptographic signature verification that allow the upload of backup files and a lack of authentication for a critical function that can cause a denial of service. Real-world exploitation has been observed, with threat actors targeting internet-exposed appliances to execute remote commands via KPluginRunProcess and deliver Base64-encoded payloads using curl. One significant incident involved a managed service provider (MSP) where the compromise exposed over 60 downstream organizations across government, healthcare, and education sectors. It is estimated that over 12,000 instances remain internet-facing and unpatched.
Recommendations Update versions 13.0.x to 13.0.385 or later. Update versions 13.1.x to 13.1.81 or later. Update versions 13.2.x to 13.2.183 or later. Update versions 14.0.x to 14.0.341 (Patch 5) or later. Update versions 14.1.x to 14.1.101 (Patch 4) or later. Remove the appliance from the public internet by using a firewall, VPN, or air-gapping the system.

Fix

RCE

Improper Verification of Cryptographic Signature

Authentication Bypass Using an Alternate Path or Channel

Missing Authentication

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10708
BDU:2026-00086
BDU:2026-00087
BDU:2026-00088
CVE-2025-32975

Affected Products

Quest Kace System Management Appliance