CVE-2021-32086: Critical severity Quest KACE Systems Deployment Appliance (SMA) vulnerability
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often, the decrypted secrets can be used to escalate privileges within KACE, or gain privileged access to unrelated systems or services.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Quest KACE Systems Deployment Appliance (SMA)to a version that resolves this vulnerability.Fixed in 11.0.273 - Compensating control
Assume secrets stored in the MySQL databases (encrypted with a hardcoded symmetric key) may be decrypted if an attacker gains access to the MySQL server or backup files; restrict access to the MySQL server and backup files to trusted users/hosts (e.g., via network isolation and tight ACL/firewall rules).