>> All posts

CVE-2025-32975: Quest KACE SMA authentication bypass, now in CISA KEV

The short version: Quest KACE Systems Management Appliance (SMA) has an authentication-bypass flaw (CVE-2025-32975) in its SSO handling that lets an attacker impersonate a legitimate user without valid credentials — and reach complete administrative takeover. It scores a perfect 10.0, and CISA has since added it to the KEV catalog. KACE manages your endpoints, so a takeover here reaches far. Steady hands — but move.

At a glance

FactDetail
Our severity takeHigh — in practice and on paper
CVSS v3.1 (NVD/CISA-ADP)10.0 — Critical · AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS2.42% · 82nd percentile (2026-07-17)
In CISA KEV?Yes — remediation due 2026-05-04 (added 2026-04-20)
Known exploited?Yes — added to KEV on evidence of exploitation
Vulnerability typeCWE-287 improper authentication → SSO impersonation → full administrative takeover
Requires authenticated session?No — pre-authentication
AffectedKACE SMA 13.0.x < 13.0.385, 13.1.x < 13.1.81, 13.2.x < 13.2.183, 14.0.x < 14.0.341 (Patch 5), 14.1.x < 14.1.101 (Patch 4)
Fixed in13.0.385 · 13.1.81 · 13.2.183 · 14.0.341 (Patch 5) · 14.1.101 (Patch 4)

What you need to know

The flaw lives in how KACE SMA handles single sign-on. A weakness in that authentication path lets an attacker present themselves as a legitimate user without ever supplying valid credentials — and because the impersonation can reach an administrative identity, it opens the door to complete control of the appliance.

That target is what makes this bad. KACE is a systems-management platform: it inventories, patches, and pushes software and scripts to the endpoints across your estate. Administrative control of it is administrative reach into everything it manages.

  • It's the management plane. Control the tool that controls your endpoints, and one appliance becomes a launchpad.
  • It's pre-authentication and network-reachable. No credential, no chain to the bypass itself.
  • The KEV clock is real. It's now listed as known-exploited with a federal remediation deadline.

How serious we see it

High — the 10.0 matches the reality.

Unauthenticated authentication bypass to full admin on a systems-management appliance, now known-exploited, is exactly the profile that goes to the top of the queue. The bounded, reassuring part is that it's specific and fixable: it affects defined KACE SMA builds, the patched versions are published, and you can confirm your version and exposure quickly. As always with a KEV-listed bug, being patched and being clean are separate questions worth checking.

Recommendations

Straight from Quest's advisory and CISA:

  1. Patch now. Upgrade to 13.0.385 / 13.1.81 / 13.2.183 / 14.0.341 (Patch 5) / 14.1.101 (Patch 4) or later.
  2. Get the appliance off the open internet. Restrict KACE SMA management access to trusted networks or a VPN.
  3. Hunt for prior use. Review authentication and admin logs for anomalous SSO logins, unexpected admin actions, and new accounts or scripts.
  4. If you find indicators, respond. Because KACE reaches your endpoints, treat a compromise as potentially estate-wide — rotate credentials and investigate downstream systems.
  5. Confirm your exposure first. Verify whether you run KACE SMA, which build, and whether it's reachable from the internet.

How BreachRisk sees it

BreachRisk discovers internet-facing KACE SMA appliances from little more than your domain, fingerprints the version, and flags exposure tied to this KEV-listed vulnerability — pushed to the top of your results because it's actively exploited. We detect and flag the exposed, affected appliance; we don't attempt the impersonation to prove it.

That outside-in, continuous view is the point: when a management-plane appliance turns out to be exploitable, the exposed device is already mapped, so you go straight to patch-and-verify instead of hunting for what you own.

References

See your cyber risk, proven.