CVE-2021-32088
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- 0.30%
- 23th pct
- KEV
- No
- Class
- other
- CWE-384
Description
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.
References
Status: profiled · ingested 2026-08-03T18:00:54.000Z