CVE-2021-32087 Details
Description
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups. Sensitive information is stored in the database, such as privileged credentials for other systems.
A vulnerability exists in Quest KACE Systems Deployment Appliance (SMA) version 11.0.273, where the application is installed with default user credentials. The kbftp account is accessible with the widely known password 'getbxf', enabling remote attackers to easily obtain privileged access to the FTP service interface. This interface contains MySQL backups, which include sensitive information such as privileged credentials for other systems.
Users can upgrade to Quest KACE Systems Management Appliance version 11.1, which addresses this vulnerability. The update is available through the Quest Support portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| quest kace systems management appliance | 11.0.273 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | Initial Analysis | [email protected] |
| Jul 28, 2026 | CVE Modified | CISA-ADP |
| Jul 27, 2026 | New CVE Received | [email protected] |