Back to overview

CVE-2021-32087

HIGH
8.8
CVSS 3.1
Description
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups. Sensitive information is stored in the database, such as privileged credentials for other systems.

Metadata

CVE ID
CVE-2021-32087
State
PUBLISHED
Assigner
mitre
Reserved
2021-05-06 00:00 UTC
Published
2026-07-27 00:00 UTC
Last updated
2026-07-28 18:47 UTC
Primary CWE
CWE-798
CWE-798 Use of Hard-coded Credentials
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

8.8 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-798 adp CWE-798 Use of Hard-coded Credentials
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.8 HIGH 3.1 adp CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Back to overview