Impact
An issue in Quest KACE Systems Deployment Appliance version 11.0.273 allows remote attackers to trivially gain privileged access to the MySQL database by using the default password box747 for the report and R1 MySQL accounts. This credential compromise means an attacker can read and potentially modify sensitive data, including privileged credentials for other systems. The weakness is due to the use of insecure default credentials and can be mapped to CWE‑798.
Affected Systems
The affected system is Quest KACE Systems Deployment Appliance, specifically version 11.0.273. No other products or versions are listed as impacted.
Risk and Exploitability
Because the attack requires only the universal default credential, the exploitation is trivial once the appliance is reachable. The EPSS score is < 1% and the vulnerability is not listed in CISA's KEV catalog, but the ease of exploitation combined with the potential to access sensitive credential data makes it a high‑risk vulnerability. Remote attackers with network access can leverage the default password to retrieve privileged information without any additional configuration or privileged permissions.
OpenCVE Enrichment