CVE-2025-32975
CVE-2025-32975 is a critical-severity vulnerability in Quest Kace Systems Management Appliance with a CVSS 3.x base score of 10.0. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2026-04-20). The underlying weakness is classified as CWE-287.
Key facts
- Severity: Critical (CVSS 3.x base score 10.0)
- EPSS exploit prediction: 2% (84th percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2026-04-20)
- EU (EUVD) id: EUVD-2025-19028
- EU exploitation: Flagged exploited in the ENISA EU Vulnerability Database (since 2026-04-20)
- Weakness: CWE-287
- Affected product: Quest Kace Systems Management Appliance
- Published:
- Last modified:
Description
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.
Frequently asked questions
- What is CVE-2025-32975?
- Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.
- How severe is CVE-2025-32975?
- CVE-2025-32975 has a CVSS 3.x base score of 10.0, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2025-32975 being actively exploited?
- Yes. CVE-2025-32975 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2026-04-20, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2025-32975?
- CVE-2025-32975 affects Quest Kace Systems Management Appliance. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-32975?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- Does CVE-2025-32975 have an EU (EUVD) identifier?
- Yes. CVE-2025-32975 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-19028. It is also flagged as exploited in the EUVD (since 2026-04-20).
- When was CVE-2025-32975 published?
- CVE-2025-32975 was published on 2025-06-24 and last updated on 2026-06-17.
References
- https://seclists.org/fulldisclosure/2025/Jun/22
- https://seralys.com/research/CVE-2025-32975.txt
- https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978
- http://seclists.org/fulldisclosure/2025/Jun/25
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32975
Affected products (1)
- cpe:2.3:a:quest:kace_systems_management_appliance:*:*:*:*:*:*:*:*
More vulnerabilities in Quest Kace Systems Management Appliance
- CVE-2021-32088 — Critical (CVSS 9.8): An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a…
- CVE-2021-32086 — Critical (CVSS 9.8): An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric…
- CVE-2021-32084 — Critical (CVSS 9.8): An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to…
- CVE-2022-30285 — Critical (CVSS 9.8): In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This…
- CVE-2022-29807 — Critical (CVSS 9.8): A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow…
- CVE-2019-12918 — Critical (CVSS 9.8): Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file…
All CVEs affecting Quest Kace Systems Management Appliance →
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-101077 — Critical (CVSS 10.0): A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp…
- CVE-2026-100886 — Critical (CVSS 10.0): A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected…
- CVE-2026-77244 — Critical (CVSS 10.0): MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0,…
- CVE-2026-94493 — Critical (CVSS 10.0): A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of…
- CVE-2026-83099 — Critical (CVSS 10.0): Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).…
- CVE-2026-83059 — Critical (CVSS 10.0): Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).…
Browse all CWE-287 (Improper Authentication) vulnerabilities →