SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2021-32088

CRITICAL · CVSS 9.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The Quest KACE Systems Deployment Appliance is vulnerable due to a flaw in its API endpoints that allows attackers to bypass rate-limiting protections by removing the kboxid cookie, potentially enabling brute-force attacks. This critical vulnerability poses a significant risk of unauthorized access to sensitive systems and data. Organizations using this appliance should prioritize immediate remediation to safeguard their environments against potential exploitation.

CVE
CVE-2021-32088
Severity
CRITICAL
CVSS
9.8
EPSS
0.29%

Original NVD Description

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.

Related CVEs

Other vulnerabilities affecting the same vendor(s)