Junglewise Threat Intelligence

CVE-2021-32086: Quest KACE SMA hardcoded symmetric encryption key

CVE-2021-32086 · Severity: info · CVSS 0 · Published 2026-07-27

Technologies: Quest KACE Systems Management Appliance, Quest KACE Systems Management Appliance (SMA). Vendors: Quest.

Executive brief

Quest KACE Systems Management Appliance (SMA) is a solution used by organizations to manage and deploy software across corporate devices. A security flaw was identified where the system uses a universal, non-unique encryption key to protect sensitive data within its internal database. If an attacker gains access to database backups or the server itself, they can easily decrypt secrets, potentially leading to full control over the appliance or unauthorized access to other connected corporate systems.

Technical details

Quest KACE Systems Management Appliance (SMA) version 11.0.273 contains a cryptographic vulnerability due to the use of a static, hardcoded symmetric encryption key for database secrets. This key is not unique per installation, meaning the same key is shared across all deployed appliances of this version. An attacker who obtains access to the MySQL server or its backup files (e.g., via local access or other vulnerabilities) can use this known key to decrypt sensitive credentials stored in the database. These decrypted secrets can facilitate privilege escalation within the KACE environment or provide lateral movement opportunities into other systems managed by the appliance. The issue is resolved in KACE SMA version 11.1.

Affected products

  • Quest KACE Systems Management Appliance (SMA) 11.0.273

Timeline

  • 2021-07-01: advisory: Initial Quest knowledge base article created
  • 2021-07-27: disclosed: CVE published to NVD
  • 2021-07-27: patched: Quest confirmed fix in version 11.1

References

Related threats