Executive brief
Quest KACE Systems Management Appliance (SMA) is an IT asset management solution used to manage and deploy software across corporate networks. A security flaw in its API allows attackers to bypass rate-limiting protections, which are designed to prevent automated password guessing. This could allow an attacker to perform brute-force attacks more effectively, potentially leading to unauthorized account access.
Technical details
A rate-limit bypass vulnerability exists in the API of Quest KACE Systems Management Appliance (SMA) version 11.0.273. The appliance implements rate-limiting on certain API endpoints to mitigate brute-force attacks; however, the tracking mechanism for these limits relies on the presence of the 'kboxid' cookie. An attacker can bypass these restrictions by programmatically removing the cookie from subsequent requests, allowing for high-frequency automated login attempts. This issue was resolved in KACE SMA version 11.1.
Affected products
- Quest KACE Systems Management Appliance (SMA) 11.0.273
Timeline
- 2021-07-01: disclosed: Initial internal KB article creation date
- 2021-07-01: patched: Fix released in version 11.1
- 2026-07-27: advisory: NVD publication date