CyberRota Analysis
AI-GeneratedThe Quest KACE Systems Deployment Appliance version 11.0.273 is vulnerable due to the use of a hardcoded symmetric encryption key for encrypting secrets in its MySQL databases, which is not unique to each installation. This flaw allows an attacker with access to the MySQL server or backup files to decrypt sensitive information, potentially leading to privilege escalation within KACE and access to other systems. Organizations using this appliance should prioritize remediation to prevent unauthorized access and mitigate the risk of data breaches.
Original NVD Description
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often, the decrypted secrets can be used to escalate privileges within KACE, or gain privileged access to unrelated systems or services.
Related CVEs
Other vulnerabilities affecting the same vendor(s)