CVE-2021-32084
Analyzed Analyzed - Analysis Complete

API Access Bypass in Quest KACE SMA

Vulnerability report for CVE-2021-32084, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-08-03

Assigner: MITRE

Description

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-08-03
Generated
2026-08-17
AI Q&A
2026-07-28
EPSS Evaluated
2026-08-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
quest kace_systems_management_appliance 11.0.273

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Quest KACE Systems Deployment Appliance (SMA) version 11.0.273. It allows API endpoints to remain accessible even when the web console is restricted by IP address or subnets. If an attacker obtains credentials or API keys, they can exploit this to access the appliance via the API and potentially compromise the entire configured environment.

Detection Guidance

To detect this vulnerability, check if API endpoints are accessible despite IP restrictions on the Quest KACE SMA web console. Verify if API access is enabled without proper authentication or IP filtering. Inspect network logs for unauthorized API requests targeting the appliance.

Impact Analysis

If you use Quest KACE SMA 11.0.273 with IP-based access restrictions, an attacker with stolen credentials or API keys could bypass these restrictions and gain unauthorized access to your appliance. This could lead to full control over your KACE environment, including deployment and management of systems, posing a significant security risk.

Compliance Impact

This vulnerability could lead to unauthorized access and potential data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Unauthorized access to systems management tools like KACE SMA could result in data exposure, loss of integrity, or failure to meet security control standards.

Mitigation Strategies

Restrict API access by IP or subnet if not already done. Ensure credentials and API keys are secured and not exposed. Review and update firewall rules to block unauthorized API access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2021-32084. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart