CVE-2021-32084
Quest · KACE Systems Deployment Appliance (SMA)
Quest KACE SMA 11.0.273 fails to enforce IP-based access restrictions on API endpoints, allowing bypass of console security.
Executive summary
A critical access control bypass in the Quest KACE Systems Deployment Appliance allows attackers to circumvent network restrictions and access API endpoints.
Vulnerability
This is an access control weakness where IP-based restrictions intended for the web console do not apply to API endpoints. An attacker who possesses valid credentials or API keys can gain unauthorized access to the appliance via the API.
Business impact
With a CVSS score of 9.8, this vulnerability is critical. It allows an attacker to bypass intended network security controls, potentially granting them administrative control over the appliance. This could lead to a total compromise of the managed environment, data exfiltration, or complete system takeover.
Remediation
Immediate Action: Review the vendor advisory at the provided link and apply all recommended configuration hardening or security updates provided by Quest.
Proactive Monitoring: Monitor API logs for connections originating from unauthorized IP addresses or suspicious credential usage patterns.
Compensating Controls: Isolate the KACE appliance management interfaces from public or untrusted network segments using strict firewall rules or VPN-only access.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a significant failure in security boundary enforcement. Administrators should treat this as a high priority and follow the vendor's guidance to secure API access and apply necessary patches or configuration changes to mitigate the risk of unauthorized access.