CVE-2021-32088

Published: Lug 28, 2026 Last Modified: Lug 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.

https://support.quest.com/download-product-select
https://support.quest.com/kace-systems-management-appliance/kb/4293505/quest-re…