SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2021-32086

CRITICAL · CVSS 9.8 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The Quest KACE Systems Deployment Appliance version 11.0.273 is vulnerable due to the use of a hardcoded symmetric encryption key for encrypting secrets in its MySQL databases, which is not unique to each installation. This flaw allows an attacker with access to the MySQL server or backup files to decrypt sensitive information, potentially leading to privilege escalation within KACE and access to other systems. Organizations using this appliance should prioritize remediation to prevent unauthorized access and mitigate the risk of data breaches.

CVE
CVE-2021-32086
Severity
CRITICAL
CVSS
9.8
EPSS
0.19%

Original NVD Description

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often, the decrypted secrets can be used to escalate privileges within KACE, or gain privileged access to unrelated systems or services.

Related CVEs

Other vulnerabilities affecting the same vendor(s)