CVE-2025-32975
About
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.
Rainforest analyst review
Quest KACE Systems Management Appliance contains an authentication bypass in its single sign-on handling. The SSO mechanism does not properly verify the authentication assertion it receives, letting a remote attacker impersonate a legitimate user, including an administrator, without presenting valid credentials. Because the flaw is in the auth layer itself rather than a post-login feature, a crafted request is enough to be treated as an authenticated privileged user, leading to complete administrative takeover of the appliance.
KACE SMA is an endpoint management platform: it inventories, patches, and deploys software across an organization's device fleet, which means administrative control of it is a direct path to pushing code to every managed endpoint. That makes an auth-bypass here a fleet-wide risk, the kind of central management system attackers specifically seek out because one compromise scales to the whole estate. Patch to the fixed builds for your line (13.0.385, 13.1.81, 13.2.183, 14.0.341 Patch 5, or 14.1.101 Patch 4) as a priority, keep the appliance off the public internet and restricted to administrative networks, and review SSO login records and administrative actions for impersonated sessions predating the fix.
References
- https://seclists.org/fulldisclosure/2025/Jun/22
- https://seralys.com/research/CVE-2025-32975.txt
- https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978
- http://seclists.org/fulldisclosure/2025/Jun/25
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32975
Related CVEs
Frequently asked questions
What is CVE-2025-32975?
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials.
How severe is CVE-2025-32975?
CVE-2025-32975 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2025-32975 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2025-32975?
Public advisories list the following as affected: kace systems management appliance. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2025-32975?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
