HomeCVE Intelligence › CVE-2025-32975
CVSS 9.5 CRITICAL 🔴 ACTIVELY EXPLOITED Vulnerability

CVE-2025-32975: Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.

⚠️ CISA KEV Remediation Due: 2026-05-04
9.5CVSS Score
CRITICALSeverity
YESCISA KEV
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2025-32975
VendorQuest
Affected ProductKACE Systems Management Appliance (SMA)
Vulnerability TypeVulnerability
CVSS Score9.5 (CRITICAL)
Actively Exploited✅ Yes — CISA KEV Listed
Patch StatusSee Vendor Advisory →
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via cisa_kev)

🔬 Technical Analysis

Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.

📚 Advisory References

⚡ DETECTION RULES AVAILABLE

Get CVE-2025-32975 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence