SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2021-32084

CRITICAL · CVSS 9.8 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The Quest KACE Systems Deployment Appliance is vulnerable due to inadequate access restrictions on its API endpoints, allowing attackers to bypass IP address or subnet restrictions if they possess valid credentials or API keys. This flaw can lead to a complete compromise of the configured environment, making it critical for organizations using KACE to prioritize immediate remediation. Security teams should focus on implementing stricter access controls and monitoring API usage to mitigate potential risks.

CVE
CVE-2021-32084
Severity
CRITICAL
CVSS
9.8
EPSS
0.33%

Original NVD Description

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE.

Related CVEs

Other vulnerabilities affecting the same vendor(s)