Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability has been identified in the Quest KACE Systems Deployment Appliance that could allow unauthorized access and control. While the exact business impact is still under evaluation, the exposure of this system through network interfaces warrants attention to confirm relevance and assess potential exposure within your environment.
- Rate limiting bypass allows unauthorized access.
- Affects critical systems management appliance.
- Confirm relevance and exposure in your environment.
Attack Path
How an attacker could exploit the issue
An attacker could bypass rate limiting on certain API endpoints of the Quest KACE Systems Deployment Appliance by removing a specific cookie. This bypass allows for brute-force attacks that could compromise the appliance's security.
- Unauthenticated access to the appliance's API.
- Removing a specific cookie to bypass rate limiting.
- Allows for brute-force attacks against the appliance.
Live Threat
Current exploitation, exposure, and threat context
The rate-limiting feature on certain API endpoints of the Quest KACE Systems Deployment Appliance could be bypassed by removing the `kboxid` cookie. This could allow an unauthorized actor to access the appliance's API.
- System and user data may be at risk.
- Bypass achieved via API request manipulation.
- Unauthorized access and potential control.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects Quest KACE Systems Deployment Appliance, likely managed by infrastructure or platform teams. The first step is to identify all instances of the appliance, assess their network reachability and business criticality, and determine the accountable owner for remediation planning.
- Identify appliance instances and assess exposure.
- Confirm appliance criticality and ownership.
- Plan remediation based on risk assessment.