← Global Threat Landscape

CVE-2025-32975

CWE-287

Critical

97.8

RPS

Description

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.

Source: NVD

Signals

CVSS
10.0
Critical · v3.1
EPSS
2.48%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Apr 2026
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-287
Published
24 Jun 2025
Last modified 21 Apr 2026

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2025-32975

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2025-32975 · RPS 97.8 · DevSecure Intelligence