Vulnerability Details CVE-2021-32088
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 22.6%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2021-32088
-
cpe:2.3:a:quest:kace_systems_management_appliance:11.0.273