CVE-2021-32087
Description
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups. Sensitive information is stored in the database, such as privileged credentials for other systems.
Summary dbcve.org
Quest KACE Systems Deployment Appliance version 11.0.273 ships with a hardcoded default credential for the kbftp account (password: getbxf). This publicly known password allows remote attackers trivial access to the FTP service, which contains MySQL database backups. These backups store sensitive information including privileged credentials for other systems.
Mitigation
Immediately change the default kbftp password to a strong, unique value, or disable the account if the FTP service is not required. Review FTP and database access logs for evidence of unauthorized access.