CVE-2025-32975: Quest KACE SMA authentication bypass, now in CISA KEV
The short version: Quest KACE Systems Management Appliance (SMA) has an authentication-bypass flaw (CVE-2025-32975) in its SSO handling that lets an attacker impersonate a legitimate user without valid credentials — and reach complete administrative takeover. It scores a perfect 10.0, and CISA has since added it to the KEV catalog. KACE manages your endpoints, so a takeover here reaches far. Steady hands — but move.
At a glance
| Fact | Detail |
|---|---|
| Our severity take | High — in practice and on paper |
| CVSS v3.1 (NVD/CISA-ADP) | 10.0 — Critical · AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 2.42% · 82nd percentile (2026-07-17) |
| In CISA KEV? | Yes — remediation due 2026-05-04 (added 2026-04-20) |
| Known exploited? | Yes — added to KEV on evidence of exploitation |
| Vulnerability type | CWE-287 improper authentication → SSO impersonation → full administrative takeover |
| Requires authenticated session? | No — pre-authentication |
| Affected | KACE SMA 13.0.x < 13.0.385, 13.1.x < 13.1.81, 13.2.x < 13.2.183, 14.0.x < 14.0.341 (Patch 5), 14.1.x < 14.1.101 (Patch 4) |
| Fixed in | 13.0.385 · 13.1.81 · 13.2.183 · 14.0.341 (Patch 5) · 14.1.101 (Patch 4) |
What you need to know
The flaw lives in how KACE SMA handles single sign-on. A weakness in that authentication path lets an attacker present themselves as a legitimate user without ever supplying valid credentials — and because the impersonation can reach an administrative identity, it opens the door to complete control of the appliance.
That target is what makes this bad. KACE is a systems-management platform: it inventories, patches, and pushes software and scripts to the endpoints across your estate. Administrative control of it is administrative reach into everything it manages.
- It's the management plane. Control the tool that controls your endpoints, and one appliance becomes a launchpad.
- It's pre-authentication and network-reachable. No credential, no chain to the bypass itself.
- The KEV clock is real. It's now listed as known-exploited with a federal remediation deadline.
How serious we see it
High — the 10.0 matches the reality.
Unauthenticated authentication bypass to full admin on a systems-management appliance, now known-exploited, is exactly the profile that goes to the top of the queue. The bounded, reassuring part is that it's specific and fixable: it affects defined KACE SMA builds, the patched versions are published, and you can confirm your version and exposure quickly. As always with a KEV-listed bug, being patched and being clean are separate questions worth checking.
Recommendations
Straight from Quest's advisory and CISA:
- Patch now. Upgrade to 13.0.385 / 13.1.81 / 13.2.183 / 14.0.341 (Patch 5) / 14.1.101 (Patch 4) or later.
- Get the appliance off the open internet. Restrict KACE SMA management access to trusted networks or a VPN.
- Hunt for prior use. Review authentication and admin logs for anomalous SSO logins, unexpected admin actions, and new accounts or scripts.
- If you find indicators, respond. Because KACE reaches your endpoints, treat a compromise as potentially estate-wide — rotate credentials and investigate downstream systems.
- Confirm your exposure first. Verify whether you run KACE SMA, which build, and whether it's reachable from the internet.
How BreachRisk sees it
BreachRisk discovers internet-facing KACE SMA appliances from little more than your domain, fingerprints the version, and flags exposure tied to this KEV-listed vulnerability — pushed to the top of your results because it's actively exploited. We detect and flag the exposed, affected appliance; we don't attempt the impersonation to prove it.
That outside-in, continuous view is the point: when a management-plane appliance turns out to be exploitable, the exposed device is already mapped, so you go straight to patch-and-verify instead of hunting for what you own.