CVE-2025-32978 Details
Description
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to replace system licenses through a web interface intended for license renewal. Attackers can exploit this to replace valid licenses with expired or trial licenses, causing denial of service.
A vulnerability exists in Quest KACE Systems Management Appliance (SMA) versions 13.0.x prior to 13.0.385, 13.1.x prior to 13.1.81, 13.2.x prior to 13.2.183, 14.0.x prior to 14.0.341 (Patch 5), and 14.1.x prior to 14.1.101 (Patch 4). This vulnerability allows unauthenticated users to replace valid system licenses with expired or trial licenses through a web interface designed for license renewal. Exploitation of this vulnerability can lead to a denial-of-service condition by corrupting the license information, disrupting administrative functions.
Quest has released patches for this vulnerability in KACE SMA versions 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5), and 14.1.101 (Patch 4). Administrators are encouraged to update to one of these versions. For KACE SMA version 13.x, the security hotfix is available on the Quest Support Portal. For version 14.0 and later, the latest version can be downloaded from the support portal or via the KACE SMA admin interface. If the update is not available, consult the KACE Auto Update guidance on the Quest Support site.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2025CISA-ADP
Assessed Jun 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://seclists.org/fulldisclosure/2025/Jun/25 | CVE | |
| https://seclists.org/fulldisclosure/2025/Jun/25 | [email protected] | AdvisoryMailing ListRemedy |
| https://seralys.com/research/CVE-2025-32978.txt | [email protected] | AdvisoryRemedy |
| https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Quest KACE Systems Management Appliance | >= 14.1, < 14.1.101 >= 14.0, < 14.0.341 >= 13.2, < 13.2.183 >= 13.1, < 13.1.81 >= 13.0, < 13.0.385 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Jun 24, 2025 | New CVE Received | [email protected] |
| Jun 24, 2025 | CVE Modified | CISA-ADP |
Volerion