Impact
Quest KACE Systems Deployment Appliance 11.0.273 deploys with a default kbftp user whose password is the hard‑coded value getbxf, a credential that is publicly documented. The FTP service exposes MySQL backups that contain privileged information for other systems, so an attacker who can reach the FTP interface can directly log in with administrative rights and retrieve sensitive data. This flaw is a classic example of hard‑coded credentials permitting remote privileged access without additional exploitation steps.
Affected Systems
The vulnerability is present in Quest KACE Systems Deployment Appliance version 11.0.273. All installations running this exact version are vulnerable unless the default kbftp password has been altered or a patch that removes the hard‑coded credential has been applied.
Risk and Exploitability
The EPSS score of <1% indicates a very low but nonzero likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 8.8 reflects high severity. Attackers only need access to the FTP interface and the known credentials to gain full administrative access, after which they can download backup files containing highly sensitive information. While exploitation may be rare, the confidentiality impact is severe, making the overall risk high for any organization running this revision of the appliance.
OpenCVE Enrichment