Known vulnerabilities in KACE Systems Management Appliance (SMA)
Vendor:
Quest Software Inc.
Software:
KACE Systems Management Appliance (SMA)
Software CPE:
cpe:2.3:a:quest_software:kace_sma:*:*:*:*:*:*:*:*
Website:
https://www.quest.com/
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU127611 - Missing Authentication for Critical Function CVE-2025-32978 |
CWE-306 | Medium | 13.0.385, 13.1.81, 13.2.183, 14.0.341, 14.1.101 | 24.04.2026 |
SB20260424172 |
||
| #VU127610 - Improper Verification of Cryptographic Signature CVE-2025-32977 |
CWE-347 | High | 13.0.385, 13.1.81, 13.2.183, 14.0.341, 14.1.101 | 24.04.2026 |
SB20260424172 |
||
| #VU127609 - Authentication Bypass Using an Alternate Path or Channel CVE-2025-32976 |
CWE-288 | Medium | 13.0.385, 13.1.81, 13.2.183, 14.0.341, 14.1.101 | 24.04.2026 |
SB20260424172 |
||
| #VU127608 - Improper Authentication CVE-2025-32975 |
CWE-287 | High | 13.0.385, 13.1.81, 13.2.183, 14.0.341, 14.1.101 | 24.04.2026 |
SB20260424172 |