HIGH

CVE-2021-32087

Quest Kace Systems Management Appliance 2026-07-27 CVSS v3.1
CVSS
8.8

Description

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups. Sensitive information is stored in the database, such as privileged credentials for other systems.

Summary dbcve.org

Quest KACE Systems Deployment Appliance version 11.0.273 ships with a hardcoded default credential for the kbftp account (password: getbxf). This publicly known password allows remote attackers trivial access to the FTP service, which contains MySQL database backups. These backups store sensitive information including privileged credentials for other systems.

Mitigation

Immediately change the default kbftp password to a strong, unique value, or disable the account if the FTP service is not required. Review FTP and database access logs for evidence of unauthorized access.

Weakness (CWE)

CWE-798 Hard-coded Credentials

EPSS Score

0.29%
Probability of exploitation in next 30 days
22.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE