CVE-2021-32087

8.8

Quest · KACE Systems Deployment Appliance (SMA)

Quest KACE SMA 11.0.273 uses a publicly documented default password for the kbftp account, allowing remote authenticated attackers to access sensitive MySQL backups and system credentials.

Executive summary

A critical security vulnerability in the Quest KACE Systems Deployment Appliance allows attackers with low-level access to gain unauthorized, privileged control over the FTP service and sensitive system data.

Vulnerability

This vulnerability is caused by the use of default credentials for the kbftp account, which utilizes the publicly known password "getbxf". An attacker with low privileges can leverage these credentials to gain full access to the FTP service interface, exposing sensitive database backups and stored administrative credentials for other systems.

Business impact

The exploitation of this vulnerability poses a severe risk to organizational security, as it provides a pathway for attackers to harvest credentials for secondary systems and exfiltrate sensitive data contained within database backups. Given the CVSS score of 8.8, this flaw represents a High severity risk that could lead to full compromise of the appliance and subsequent lateral movement within the network. The potential for unauthorized access to stored privileged credentials significantly increases the scope of the impact beyond the appliance itself.

Remediation

Immediate Action: Administrators must immediately change the default password for the kbftp account and follow the vendor guidance provided in the Quest support knowledge base to secure the FTP interface.

Proactive Monitoring: Security teams should monitor network access logs for anomalous connections to the FTP service and audit the appliance for unauthorized file access or data staging activity.

Compensating Controls: Restrict access to the FTP service via firewall rules to only authorized management IP addresses to prevent unauthorized remote exploitation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The presence of default, publicly known credentials in a management appliance is a critical failure that must be addressed immediately. Administrators should prioritize the password rotation for the identified account and perform a comprehensive audit of the appliance to ensure no unauthorized access has already occurred. Given the potential for credential theft and lateral movement, this remediation should be treated with high urgency.

More Quest CVEs

Sources