Description
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Quest KACE Systems Deployment Appliance (SMA) version 11.0.273 implements rate‑limiting on certain API endpoints to reduce brute‑force authentication attempts. The limiter relies on a cookie named kboxid; if an attacker removes or fails to send this cookie, the rate‑limiting is disabled. Based on the description, it is inferred that the attacker can manipulate the cookie via direct HTTP request modification. Consequently, an adversary can send an unlimited number of requests, thereby bypassing the authentication guard and potentially gaining unauthorized access to management functions, although the flaw does not provide direct code execution.

Affected Systems

The only affected product is Quest KACE Systems Deployment Appliance (SMA) 11.0.273. No other vendors or product versions are listed as impacted.

Risk and Exploitability

Based on the description, it is inferred that the attack vector is remote via HTTP API; the exploit merely requires the ability to send HTTP requests and manipulate cookie data. Because the exploit requires only the ability to send requests and manipulate the cookie, any host that can reach the appliance’s API can attack. The CVSS score of 9.8 reflects the high impact of the authentication bypass, while the EPSS score of < 1 % indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker could rapidly delete the kboxid cookie and flood the endpoint, effectively nullifying the rate‑limiting defense and enabling brute‑force credential attempts.

Generated by OpenCVE AI on August 5, 2026 at 00:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the appliance to the latest version provided by Quest once a patch addressing the cookie bypass is released.
  • Restrict external access to the SMA API endpoints by configuring firewall rules or network segmentation to allow traffic only from trusted administrative hosts.
  • Enable monitoring and alerting for repeated authentication request patterns or absence of the kboxid cookie, and investigate anomalies promptly.

Generated by OpenCVE AI on August 5, 2026 at 00:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Rate‑Limiting Bypass in Quest KACE SMA via kboxid Cookie Removal

Sun, 02 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Rate‑Limiting Bypass via Cookie Removal in Quest KACE SMA
Weaknesses CWE-307

Thu, 30 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Rate‑Limiting Bypass via Cookie Removal in Quest KACE SMA
Weaknesses CWE-307

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-384
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Quest
Quest kace Systems Deployment Appliance
Vendors & Products Quest
Quest kace Systems Deployment Appliance

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.
References

Subscriptions

Quest Kace Systems Deployment Appliance Kace Systems Management Appliance
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-28T16:01:46.198Z

Reserved: 2021-05-06T00:00:00.000Z

Link: CVE-2021-32088

cve-icon Vulnrichment

Updated: 2026-07-28T16:01:36.456Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T22:16:57.840

Modified: 2026-08-03T14:30:47.763

Link: CVE-2021-32088

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:45:03Z

Weaknesses