Junglewise Threat Intelligence

CVE-2021-32085: Quest KACE SMA default credentials in MySQL database

CVE-2021-32085 · Severity: info · CVSS 9.8 · Published 2026-07-27

Technologies: Quest KACE Systems Management Appliance, Quest KACE Systems Management Appliance (SMA). Vendors: Quest.

Executive brief

Quest KACE Systems Management Appliance (SMA) is an IT management tool used to inventory hardware and software, manage patches, and deploy applications. A security flaw was identified where the appliance installs with well-known, default passwords for its internal database. An attacker could use these credentials to gain full access to the database, potentially exposing sensitive information such as administrative credentials for other systems managed by the appliance.

Technical details

Quest KACE Systems Management Appliance (SMA) version 11.0.273 installs with hardcoded, publicly documented default credentials for the 'report' and 'R1' MySQL database accounts (password: 'box747'). This vulnerability allows a remote attacker with network access to the database service to authenticate without authorization. Once authenticated, the attacker can access sensitive information stored within the database, including privileged credentials for other systems managed by the appliance. This issue was resolved in KACE SMA version 11.1.

Affected products

  • Quest KACE Systems Management Appliance (SMA) 11.0.273

Timeline

  • 2021-07-01: advisory: Initial Quest KB article published
  • 2026-07-27: disclosed: CVE published to NVD

References

Related threats