Improper Verification of Cryptographic Signature in KACE Systems Management Appliance (SMA) - CVE-2025-32977
Published: April 24, 2026
KACE Systems Management Appliance (SMA)
Detailed vulnerability description
The vulnerability allows a remote attacker to upload malicious backup content.
The vulnerability exists due to improper verification of cryptographic signature in the backup upload functionality when processing uploaded backup files. A remote attacker can upload a specially crafted backup file to upload malicious backup content.
User interaction is required.