← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-32086

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often, the decrypted secrets can be used to escalate privileges within KACE, or gain privileged access to unrelated systems or services.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.10%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-321 ↗CWE-321 Use of Hard-coded Cryptographic Key

Affected Products & Versions

Vendor Product Affected Versions
quest kace_systems_management_appliance 11.0.273

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.096%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2021-05-06T00:00:00
Published2026-07-27T00:00:00
Last Updated2026-07-28T14:54:54

LINK COPIED TO CLIPBOARD