Executive brief
Quest KACE Systems Management Appliance (SMA) is a tool used by organizations to manage and secure computers, servers, and connected devices. A critical security flaw allows unauthorized individuals to bypass login requirements and impersonate legitimate users, including administrators. This could lead to a complete takeover of the management system, allowing attackers to access sensitive data or disrupt IT operations across the entire network.
Technical details
An improper authentication vulnerability (CWE-287) exists in the Single Sign-On (SSO) authentication handling mechanism of the Quest KACE Systems Management Appliance (SMA). The flaw allows a remote, unauthenticated attacker to bypass security checks and impersonate any legitimate user, including those with administrative privileges. This vulnerability is exploitable over the network without user interaction. Successful exploitation results in a complete administrative takeover of the appliance. Patches have been released for versions 13.0, 13.1, 13.2, 14.0, and 14.1.
Affected products
- Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4)
Timeline
- 2025-06-24: disclosed: Initial CVE publication
- 2026-04-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog