CVE-2021-32085
Quest · KACE Systems Deployment Appliance (SMA)
Quest KACE SMA 11.0.273 is shipped with publicly known default credentials for its MySQL database accounts.
Executive summary
The use of hardcoded, publicly known default credentials for MySQL accounts in the Quest KACE SMA appliance enables unauthorized privileged access.
Vulnerability
The appliance installs with default user credentials for the report and R1 MySQL accounts, specifically using the password "box747". This allows remote attackers to authenticate with the database and gain privileged access.
Business impact
With a CVSS score of 8.8, this vulnerability poses a high risk to the confidentiality and integrity of the system. An attacker gaining access to the underlying MySQL database can extract sensitive information, modify appliance data, or potentially escalate privileges to achieve full system control.
Remediation
Immediate Action: Change the default passwords for all database accounts immediately, as outlined in the vendor advisory.
Proactive Monitoring: Monitor database logs for unauthorized query activity or logins originating from unexpected sources.
Compensating Controls: Restrict network access to the database management ports to only authorized administrative hosts.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Immediate password rotation for all default accounts is required to remediate this vulnerability. Administrators must ensure that no default credentials remain in use on any production appliance to prevent trivial unauthorized access to sensitive database components.