peter bassill · operator
$ cve CVE-2025-32975 JSON

CVE-2025-32975 KEV

10.0
CRITICAL · CVSS 3.1 · EPSS 2.5% (pctl 84)

Patch first

On CISA KEV — known exploited in the wild, due 2026-05-04.

Description

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS2.49% — more likely to be exploited than 84% of all CVEs
WeaknessCWE-287
On CISA KEVyes — remediate by 2026-05-04
Public exploitnone known
Published2025-06-24
Last modified2026-06-17

CISA KEV

NameQuest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
Added2026-04-20
Due2026-05-04
Vendor / productQuest / KACE Systems Management Appliance (SMA)
Ransomware usenone reported

Affected (1)

VendorProduct
questkace systems management appliance

References

→ the Explorer  ·  watch your stack  ·  NVD