CVE-2021-32088
Analyzed Analyzed - Analysis Complete

Authentication Bypass in Quest KACE SMA via Cookie Removal

Vulnerability report for CVE-2021-32088, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-08-03

Assigner: MITRE

Description

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-08-03
Generated
2026-08-17
AI Q&A
2026-07-28
EPSS Evaluated
2026-08-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
quest kace_systems_management_appliance 11.0.273

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-384 Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints have rate-limiting to prevent brute-force attacks. Attackers can bypass this protection by removing the kboxid cookie.

Detection Guidance

To detect this vulnerability, monitor API endpoints in Quest KACE SMA 11.0.273 for requests missing the kboxid cookie despite rate-limiting. Check logs for repeated failed attempts bypassing protections.

Impact Analysis

An attacker could exploit this to perform brute-force attacks on the API endpoints, potentially gaining unauthorized access to the system or sensitive data.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it relates to a bypass of rate-limiting protections in Quest KACE SMA. However, if exploited, it could lead to unauthorized access, which may indirectly impact compliance by violating data protection requirements.

Mitigation Strategies

Apply vendor patches or updates for Quest KACE SMA 11.0.273 to address the rate-limiting bypass issue. Review and restrict access to API endpoints to prevent unauthorized manipulation of cookies like kboxid.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2021-32088. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart