Junglewise Threat Intelligence

CVE-2021-32088: Quest KACE SMA rate limit bypass in API login

CVE-2021-32088 · Severity: info · Published 2026-07-27

Technologies: Quest KACE Systems Management Appliance, Quest KACE Systems Management Appliance (SMA). Vendors: Quest.

Executive brief

Quest KACE Systems Management Appliance (SMA) is an IT asset management solution used to manage and deploy software across corporate networks. A security flaw in its API allows attackers to bypass rate-limiting protections, which are designed to prevent automated password guessing. This could allow an attacker to perform brute-force attacks more effectively, potentially leading to unauthorized account access.

Technical details

A rate-limit bypass vulnerability exists in the API of Quest KACE Systems Management Appliance (SMA) version 11.0.273. The appliance implements rate-limiting on certain API endpoints to mitigate brute-force attacks; however, the tracking mechanism for these limits relies on the presence of the 'kboxid' cookie. An attacker can bypass these restrictions by programmatically removing the cookie from subsequent requests, allowing for high-frequency automated login attempts. This issue was resolved in KACE SMA version 11.1.

Affected products

  • Quest KACE Systems Management Appliance (SMA) 11.0.273

Timeline

  • 2021-07-01: disclosed: Initial internal KB article creation date
  • 2021-07-01: patched: Fix released in version 11.1
  • 2026-07-27: advisory: NVD publication date

References

Related threats