PT-2026-65307 · Quest · Kace Systems Deployment Appliance

CVE-2021-32085

·

Published

2026-07-27

·

Updated

2026-08-03

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quest KACE Systems Deployment Appliance (SMA) version 11.0.273
Description The software installs with default user credentials for the report and R1 MySQL accounts, using the publicly known password box747. This allows remote attackers to gain privileged access to the MySQL databases, which contain sensitive information including privileged credentials for other systems.
Recommendations Change the default passwords for the report and R1 MySQL accounts for version 11.0.273.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32085

Affected Products

Kace Systems Deployment Appliance