Improper Authentication in KACE Systems Management Appliance (SMA) - CVE-2025-32975

 

Improper Authentication in KACE Systems Management Appliance (SMA) - CVE-2025-32975

Published: April 24, 2026


Vulnerability identifier: #VU127608
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-32975
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication and impersonate legitimate users.

The vulnerability exists due to improper authentication in the SSO authentication handling mechanism when processing authentication requests. A remote attacker can impersonate any valid username to bypass authentication and impersonate legitimate users.

The issue can lead to complete administrative takeover of the appliance.


Affected software

KACE Systems Management Appliance (SMA)

How to mitigate CVE-2025-32975

Install security update from vendor's website.

KACE Systems Management Appliance (SMA) - addressed in versions 13.0.385, 13.1.81, 13.2.183, 14.0.341, 14.1.101

External References

Related Security Bulletins