CVE-2025-32978: High severity Quest KACE Systems Management Appliance vulnerability
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to replace system licenses through a web interface intended for license renewal. Attackers can exploit this to replace valid licenses with expired or trial licenses, causing denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32978?
CVE-2025-32978 is classified as a critical vulnerability due to its ability to allow unauthenticated users to replace system licenses.
How can I fix CVE-2025-32978?
To remediate CVE-2025-32978, update your Quest KACE Systems Management Appliance to the latest version as specified in the vendor's patch notes.
Which versions of Quest KACE Systems Management Appliance are affected by CVE-2025-32978?
CVE-2025-32978 affects versions prior to 13.0.385, 13.1.81, 13.2.183, 14.0.341, and 14.1.101.
What type of access does CVE-2025-32978 exploit?
CVE-2025-32978 specifically exploits unauthorized access through a web interface intended for license renewal.
Is there a known exploit for CVE-2025-32978?
Yes, CVE-2025-32978 has a known exploit that allows attackers to change licenses without authentication.