EN
en direct
éditeur

Quest

5
vulnérabilités suivies
3
critiques
27 juillet 2026
dernière publication
cve

Veille des vulnérabilités

identifiantvulnérabilitésévéritépublié
CVE-2021-32084An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE.Quest Kace Systems Management Appliance Critique CVSS 9.8 27/07 CVE-2021-32085An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the MySQL databases. Sensitive information is stored in the database, such as privileged credentials for other systems.Quest Kace Systems Management Appliance Élevée CVSS 8.8 27/07 CVE-2021-32086An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often, the decrypted secrets can be used to escalate privileges within KACE, or gain privileged access to unrelated systems or services.Quest Kace Systems Management Appliance Critique CVSS 9.8 27/07 CVE-2021-32087An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups. Sensitive information is stored in the database, such as privileged credentials for other systems.Quest Kace Systems Management Appliance Élevée CVSS 8.8 27/07 CVE-2021-32088An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.Quest Kace Systems Management Appliance Critique CVSS 9.8 27/07

Tapez au moins deux caractères.

naviguer ouvrir esc fermer