Description
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains a logic flaw in its two-factor authentication implementation that allows authenticated users to bypass TOTP-based 2FA requirements. The vulnerability exists in the 2FA validation process and can be exploited to gain elevated access.
INFO
Published Date :
2025-06-24T00:00:00.000Z
Last Modified :
2025-11-03T19:53:51.666Z
Source :
mitre
AFFECTED PRODUCTS
The following products are affected by CVE-2025-32976 vulnerability.
| Vendors | Products |
|---|---|
| Quest |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-32976.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact