VYPR

Kace Systems Deployment Appliance

by Quest

CVEs (6)

  • CVE-2023-33254MedMay 21, 2023
    risk 0.43cvss 6.5epss 0.03

    There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a higher privilege level on the Active Directory domain. To exploit this, an authenticated attacker edits the user-authentication…

  • CVE-2021-32088CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.

  • CVE-2021-32087HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.00

    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to…

  • CVE-2021-32086CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a…

  • CVE-2021-32085HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.00

    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain…

  • CVE-2021-32084CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be…