External risk intelligence

Quest KACE SMA API Rate Limiting Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2021-32088

The Quest KACE Systems Management Appliance is designed to manage network assets and endpoints. Such appliances are commonly deployed in configurations where they are reachable via a management interface or API over a network, and in many enterprise environments, these gateways are exposed to authorized network segments or directly to the internet to facilitate remote management.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in the Quest KACE Systems Deployment Appliance that could allow unauthorized access and control. While the exact business impact is still under evaluation, the exposure of this system through network interfaces warrants attention to confirm relevance and assess potential exposure within your environment.

  • Rate limiting bypass allows unauthorized access.
  • Affects critical systems management appliance.
  • Confirm relevance and exposure in your environment.

Attack Path

How an attacker could exploit the issue

An attacker could bypass rate limiting on certain API endpoints of the Quest KACE Systems Deployment Appliance by removing a specific cookie. This bypass allows for brute-force attacks that could compromise the appliance's security.

  • Unauthenticated access to the appliance's API.
  • Removing a specific cookie to bypass rate limiting.
  • Allows for brute-force attacks against the appliance.

Live Threat

Current exploitation, exposure, and threat context

The rate-limiting feature on certain API endpoints of the Quest KACE Systems Deployment Appliance could be bypassed by removing the `kboxid` cookie. This could allow an unauthorized actor to access the appliance's API.

  • System and user data may be at risk.
  • Bypass achieved via API request manipulation.
  • Unauthorized access and potential control.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Quest KACE Systems Deployment Appliance, likely managed by infrastructure or platform teams. The first step is to identify all instances of the appliance, assess their network reachability and business criticality, and determine the accountable owner for remediation planning.

  • Identify appliance instances and assess exposure.
  • Confirm appliance criticality and ownership.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Quest KACE Systems Deployment Appliance?

It is an enterprise management solution, specifically version 11.0.273, designed to automate software deployment, configuration, and endpoint maintenance. As a centralized hub, it manages critical infrastructure, which makes securing its API and administrative interfaces essential for organizational security.

How is the vulnerability classified regarding weakness?

This issue is categorized under CWE-384, which relates to session fixation or improper session management. In this instance, the appliance fails to adequately secure session-dependent state, allowing the security control mechanism to be bypassed.

How can the rate-limiting protection be triggered?

The protection on specific API endpoints is bypassed by simply removing the kboxid cookie from the request. This action eliminates the restriction mechanism, allowing subsequent requests to proceed without the intended brute-force limitations.

Is this vulnerability relevant to my environment?

According to the Halo Surface Signal, this is likely relevant because the appliance is often reachable via management interfaces or APIs over a network. Many enterprises expose these gateways to facilitate remote administration, potentially increasing the attack surface.

What is the recommended first step for response?

Begin by identifying all active instances of the appliance within your network. Once located, assess their network reachability, determine their business criticality, and verify ownership to initiate an informed remediation and risk management plan.

References