CVE-2025-32975

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:quest:kace_systems_management_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:quest:kace_systems_management_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:quest:kace_systems_management_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:quest:kace_systems_management_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:quest:kace_systems_management_appliance:*:*:*:*:*:*:*:*

History

21 Apr 2026, 14:09

Type Values Removed Values Added
References () https://seclists.org/fulldisclosure/2025/Jun/22 - () https://seclists.org/fulldisclosure/2025/Jun/22 - Mailing List, Third Party Advisory
References () https://seralys.com/research/CVE-2025-32975.txt - () https://seralys.com/research/CVE-2025-32975.txt - Third Party Advisory
References () https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978 - () https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978 - Vendor Advisory
References () http://seclists.org/fulldisclosure/2025/Jun/25 - () http://seclists.org/fulldisclosure/2025/Jun/25 - Mailing List, Third Party Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32975 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32975 - US Government Resource
First Time Quest
Quest kace Systems Management Appliance
CPE cpe:2.3:a:quest:kace_systems_management_appliance:*:*:*:*:*:*:*:*

20 Apr 2026, 20:16

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32975 -

03 Nov 2025, 20:18

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Jun/25 -

26 Jun 2025, 18:58

Type Values Removed Values Added
Summary
  • (es) Quest KACE Systems Management Appliance (SMA) 13.0.x (anterior a la 13.0.385), 13.1.x (anterior a la 13.1.81), 13.2.x (anterior a la 13.2.183), 14.0.x (anterior a la 14.0.341 [Parche 5]) y 14.1.x (anterior a la 14.1.101 [Parche 4]) contienen una vulnerabilidad de omisión de autenticación que permite a los atacantes suplantar la identidad de usuarios legítimos sin credenciales válidas. Esta vulnerabilidad se encuentra en el mecanismo de gestión de la autenticación SSO y puede provocar la toma de control administrativo completo.

24 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-24 15:15

Updated : 2026-04-21 14:09


NVD link : CVE-2025-32975

Mitre link : CVE-2025-32975

CVE.ORG link : CVE-2025-32975


JSON object : View

Products Affected

quest

  • kace_systems_management_appliance
CWE
CWE-287

Improper Authentication