Executive brief
Quest KACE Systems Management Appliance (SMA) contains a security flaw where network access restrictions applied to the web management console do not apply to the application's API. If an attacker obtains valid credentials or API keys, they can bypass IP-based access controls to manage the appliance remotely. This could lead to a full compromise of the KACE environment, potentially allowing unauthorized changes to managed systems across the organization.
Technical details
An access control bypass vulnerability exists in Quest KACE Systems Management Appliance (SMA) version 11.0.273. While the appliance allows administrators to restrict web console access to specific IP addresses or subnets, these restrictions are not enforced on API endpoints. An attacker with valid credentials or API keys can interact with the API from any network location, bypassing intended perimeter or host-based access controls. This allows for unauthorized administrative actions and potential environment-wide compromise. The issue is resolved in KACE SMA version 11.1.
Affected products
- Quest KACE Systems Management Appliance (SMA) 11.0.273
Timeline
- 2021-07-01: disclosed: Initial internal KB article creation date
- 2026-07-27: advisory: NVD publication date
- 2021-07-01: patched: Resolved in version 11.1