PT-2025-26741 · Quest · Quest Kace System Management Appliance

Mohamed Mahmoudi

+1

·

Published

2025-06-24

·

Updated

2026-03-20

·

CVE-2025-32976

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Quest KACE Systems Management Appliance (SMA) versions 13.0.x through 13.0.384 Quest KACE Systems Management Appliance (SMA) versions 13.1.x through 13.1.80 Quest KACE Systems Management Appliance (SMA) versions 13.2.x through 13.2.182 Quest KACE Systems Management Appliance (SMA) versions 14.0.x through 14.0.340 (Patch 4) Quest KACE Systems Management Appliance (SMA) versions 14.1.x through 14.1.100 (Patch 3)
Description: The issue is related to a logic flaw in the two-factor authentication implementation of the Quest KACE Systems Management Appliance (SMA), allowing authenticated users to bypass TOTP-based 2FA requirements. This flaw exists in the 2FA validation process and can be exploited to gain elevated access.
Recommendations: For versions 13.0.x through 13.0.384, update to version 13.0.385 or later. For versions 13.1.x through 13.1.80, update to version 13.1.81 or later. For versions 13.2.x through 13.2.182, update to version 13.2.183 or later. For versions 14.0.x through 14.0.340 (Patch 4), update to version 14.0.341 (Patch 5) or later. For versions 14.1.x through 14.1.100 (Patch 3), update to version 14.1.101 (Patch 4) or later.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00086
CVE-2025-32976

Affected Products

Quest Kace System Management Appliance