Junglewise Threat Intelligence

CVE-2021-32087: Quest KACE SMA default credentials in FTP service

CVE-2021-32087 · Severity: info · CVSS 9.8 · Published 2026-07-27

Technologies: Quest KACE Systems Management Appliance, Quest KACE Systems Management Appliance (SMA). Vendors: Quest.

Executive brief

Quest KACE Systems Management Appliances (SMA) are used by organizations to manage and deploy software across their networks. A security flaw was identified where the appliance ships with a publicly known default password for its file transfer (FTP) service. An attacker can use these credentials to access the system's database backups, which may contain sensitive information like administrative passwords for other corporate systems, potentially leading to a full network compromise.

Technical details

Quest KACE Systems Management Appliance (SMA) version 11.0.273 contains a hardcoded credentials vulnerability. The 'kbftp' account is configured with a default password of 'getbxf', which is publicly documented. A remote, unauthenticated attacker can use these credentials to access the FTP service interface. This interface provides access to MySQL database backups, which contain sensitive information including privileged credentials for other managed systems. The issue is resolved in KACE SMA version 11.1.

Affected products

  • Quest KACE Systems Management Appliance (SMA) 11.0.273

Timeline

  • 2021-07-01: disclosed: Initial internal KB article creation date
  • 2021-07-01: patched: Fix released in version 11.1
  • 2026-07-27: advisory: NVD publication date

References

Related threats