CVE-2021-32088: Critical severity Quest KACE Systems Deployment Appliance (SMA) vulnerability
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32088?
CVE-2021-32088 has a critical severity rating of 9.8 according to the CVSS 3.1 scoring system.
How do I fix CVE-2021-32088?
To fix CVE-2021-32088, you should upgrade to the latest version of the Quest KACE Systems Deployment Appliance that addresses this vulnerability.
What impact does CVE-2021-32088 have on the system?
CVE-2021-32088 allows attackers to bypass rate-limiting on certain API endpoints, potentially making the system vulnerable to brute-force attacks.
Is CVE-2021-32088 exploitable remotely?
Yes, CVE-2021-32088 is remotely exploitable as it affects API endpoints that can be accessed without authentication.
What product is affected by CVE-2021-32088?
CVE-2021-32088 affects the Quest KACE Systems Deployment Appliance version 11.0.273.