CVE-2025-32975: Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.
Other sources
Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Quest KACE Systems Management Appliance (SMA)to a version that resolves this vulnerability.Fixed in 13.0.385 - Upgrade
Upgrade
Quest KACE Systems Management Appliance (SMA)to a version that resolves this vulnerability.Fixed in 13.1.81 - Upgrade
Upgrade
Quest KACE Systems Management Appliance (SMA)to a version that resolves this vulnerability.Fixed in 13.2.183 - Upgrade
Upgrade
Quest KACE Systems Management Appliance (SMA)to a version that resolves this vulnerability.Fixed in 14.0.341Patch Patch 5 - Upgrade
Upgrade
Quest KACE Systems Management Appliance (SMA)to a version that resolves this vulnerability.Fixed in 14.1.101Patch Patch 4 - Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32975?
CVE-2025-32975 is classified as a high severity authentication bypass vulnerability.
How do I fix CVE-2025-32975?
To fix CVE-2025-32975, update your Quest KACE Systems Management Appliance to at least version 13.0.385, 13.1.81, 13.2.183, 14.0.341, or 14.1.101.
What can attackers do with CVE-2025-32975?
Attackers exploiting CVE-2025-32975 can impersonate legitimate users, potentially gaining unauthorized access to sensitive data.
Which versions of Quest KACE Systems Management Appliance are affected by CVE-2025-32975?
CVE-2025-32975 affects versions prior to 13.0.385, 13.1.81, 13.2.183, 14.0.341, and 14.1.101.
Is there a known exploit for CVE-2025-32975?
While specific exploit details may vary, CVE-2025-32975 is known to allow user impersonation without proper authentication.