PT-2026-65309 · Quest · Kace Systems Deployment Appliance

CVE-2021-32087

·

Published

2026-07-27

·

Updated

2026-08-03

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quest KACE Systems Deployment Appliance (SMA) version 11.0.273
Description The software installs with default user credentials. Specifically, the kbftp account uses a publicly known password getbxf. This allows remote attackers to gain privileged access to the FTP service interface, which stores MySQL backups containing sensitive information, including privileged credentials for other systems.
Recommendations Change the default password for the kbftp account on version 11.0.273.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32087

Affected Products

Kace Systems Deployment Appliance