Quest KACE Systems Management Appliance contains an authentication bypass vulnerability allowing attackers to impersonate legitimate users and gain complete administrative control without valid credentials. This is a critical CVSS 10.0 vulnerability with active exploitation confirmed by CISA KEV listing.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-06-24
Added to CISA KEV: 2026-04-20 300 DAYS BETWEEN CVE AND KEV
CVE-2025-32975 is a critical authentication bypass vulnerability affecting the Quest KACE Systems Management Appliance (SMA) [4] [2]. With a CVSS score of 10.0, it represents a severe security risk that allows for the complete compromise of affected systems [1] [3].
| Feature | Description |
|---|---|
| Vulnerability Type | Authentication Bypass (SSO handling mechanism) [5] |
| CVSS Score | 10.0 (Critical) [1] |
| Exploitation | Active in the wild (observed since March 2026) [1] |
| Requirements | Network-reachable; no credentials or user interaction required [3] |
| Impact | Complete administrative takeover [5] |
CVE-2025-32975 (CVSS score: 10.0) refers to an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. Successful exploitation of the flaw could facilitate the complete takeover of administrative accounts. The issue was patched by Quest in…
CVE-2025-32975 Overview CVE-2025-32975 is a critical authentication bypass vulnerability affecting Quest KACE Systems Management Appliance (SMA). The vulnerability exists in the SSO authentication handling mechanism and allows attackers to impersonate legitimate users without valid credentials, pote…
CVE-2025-32975 is a critical authentication bypass vulnerability in KACE SMA's SSO authentication handling mechanism with a CVSS score of 10.0. The flaw allows an unauthenticated, network-reachable attacker to impersonate legitimate users, including administrators, without supplying any credentials.
CVE-2025-32975 Detail. Description. Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81 ... An official website of the United States government NVD MENU…
CVE-2025-32975: Arctic Wolf Observes Exploitation of Quest KACE Systems Management Appliance. Arctic Wolf has observed malicious activity in ... CVE-2025-32975 is a critical authentication bypass vulnerability that allows threat actors to impersonate legitimate users without valid credentials. The f…