CVE-2021-32088

CRITICAL

Quest KACE Systems Management Appliance 11.0.273 - Unauthenticated Brute-Force Attack via kboxid Cookie Removal

Title source: llm
STIX 2.1

Description

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.

Scores

CVSS v3 9.8
EPSS 0.0030
EPSS Percentile 22.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-384
Status published
Published Jul 27, 2026
Tracked Since Jul 28, 2026