Description
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the MySQL databases. Sensitive information is stored in the database, such as privileged credentials for other systems.
Published: 2026-07-27
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in Quest KACE Systems Deployment Appliance version 11.0.273 allows remote attackers to trivially gain privileged access to the MySQL database by using the default password box747 for the report and R1 MySQL accounts. This credential compromise means an attacker can read and potentially modify sensitive data, including privileged credentials for other systems. The weakness is due to the use of insecure default credentials and can be mapped to CWE‑798.

Affected Systems

The affected system is Quest KACE Systems Deployment Appliance, specifically version 11.0.273. No other products or versions are listed as impacted.

Risk and Exploitability

Because the attack requires only the universal default credential, the exploitation is trivial once the appliance is reachable. The EPSS score is < 1% and the vulnerability is not listed in CISA's KEV catalog, but the ease of exploitation combined with the potential to access sensitive credential data makes it a high‑risk vulnerability. Remote attackers with network access can leverage the default password to retrieve privileged information without any additional configuration or privileged permissions.

Generated by OpenCVE AI on August 5, 2026 at 00:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Change the default MySQL credentials to a strong, unique password and disable or secure the default accounts
  • Restrict database access to trusted network segments or VPN only, and enforce least privilege for database users
  • Apply the latest patch or upgrade to a version of KACE SMA where default credentials are removed or protected by the vendor, if available

Generated by OpenCVE AI on August 5, 2026 at 00:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Default Credentials in Quest KACE SMA Allow Remote Database Access

Tue, 04 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Title Default MySQL Credentials in Quest KACE SMA Enable Privileged Database Access
Weaknesses CWE-256
CWE-284

Thu, 30 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Quest
Quest kace Systems Deployment Appliance
Vendors & Products Quest
Quest kace Systems Deployment Appliance

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Default MySQL Credentials in Quest KACE SMA Enable Privileged Database Access
Weaknesses CWE-256
CWE-284
CWE-798
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the MySQL databases. Sensitive information is stored in the database, such as privileged credentials for other systems.
References

Subscriptions

Quest Kace Systems Deployment Appliance Kace Systems Management Appliance
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-28T14:55:00.720Z

Reserved: 2021-05-06T00:00:00.000Z

Link: CVE-2021-32085

cve-icon Vulnrichment

Updated: 2026-07-28T14:35:57.549Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T22:16:57.500

Modified: 2026-08-03T14:31:07.000

Link: CVE-2021-32085

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:15:04Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials