CVE-2021-32088
Quest KACE Systems Deployment Appliance (SMA) 11.0.273 contains a critical flaw that lets attackers bypass API rate limiting by removing the kboxid cookie. This allows unlimited requests to the API, potentially leading to denial of service or brute‑force attacks. The vulnerability is rated CVSS 9.8.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Quest KACE Systems Deployment Appliance (SMA) version 11.0.273. Users running this version are affected.
Real-world impact
An attacker could send unlimited requests to the API, potentially causing denial of service or enabling brute‑force attacks against the system.
Why this severity
The CVSS score is high because the flaw allows attackers to bypass security controls without authentication, giving them full control over confidentiality, integrity, and availability of the affected system.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources