Vulnerability Description
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to upload backup files to the system. While signature validation is implemented, weaknesses in the validation process can be exploited to upload malicious backup content that could compromise system integrity.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://seclists.org/fulldisclosure/2025/Jun/24
- https://seralys.com/research/CVE-2025-32977.txt
- https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-
- http://seclists.org/fulldisclosure/2025/Jun/25
FAQ
What is CVE-2025-32977?
CVE-2025-32977 is a vulnerability with a CVSS score of 9.6 (CRITICAL). Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unaut...
How severe is CVE-2025-32977?
CVE-2025-32977 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-32977?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.