Impact
The vulnerability allows an attacker who knows valid credentials or API keys to access the Quest KACE Systems Deployment Appliance via its API endpoints, even when IP-based restrictions are applied to the web console. This lack of authorization on the API surface means an attacker can gain the same level of control as a legitimate administrator, potentially exposing or altering all configuration settings and data. The weakness is a classic case of improper authorization.
Affected Systems
Quest KACE Systems Deployment Appliance version 11.0.273 is affected. No other versions are listed in the official CNA data.
Risk and Exploitability
Because the API is reachable from any network location, an attacker only needs network access to the appliance and valid credentials. The EPSS score is <1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed public exploitation yet. However, once credentials are compromised, exploitation is straightforward and could lead to a complete takeover of the managed environment. The CVSS score is 9.8, but the potential impact warrants high risk from a security perspective.
OpenCVE Enrichment