← Vulnerability feed

Vulnerability record · CVE-2021-32084 · published 27 July 2026

CVE-2021-32084: Quest kace systems management appliance improper access control vulnerability

Quest · Kace Systems Management Appliance

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE.

9.8 CVSS 3.1 Critical EPSS 0.56% · top 55.9% CWE-284 · Improper access control
9.8CVSS 3.1 base score
0.56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
3 Aug 2026Last modified by NVD

Description

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-32084 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32975Quest KACE SMA SSO authentication bypass allows admin takeoverQuest KACE Systems Management Appliance contains an authentication bypass in its SSO authentication handling, letting attackers impersonate legitimat…KEVEPSS 2.5%analysed9.8CVE-2021-32086Quest kace systems management appliance vulnerabilityAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in…EPSS 0.33%9.8CVE-2021-32088Quest kace systems management appliance vulnerabilityAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize …EPSS 0.52%9.8CVE-2022-29807Quest kace systems management appliance sql injection vulnerabilityA SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via d…EPSS 1.4%9.8CVE-2022-30285Quest kace systems management appliance inadequate encryption strength vulnerabilityIn Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with…EPSS 0.55%9.8CVE-2019-12918Quest kace systems management appliance sql injection vulnerabilityQuest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and a…EPSS 1.1%9.8CVE-2017-12567Quest kace asset management appliance sql injection vulnerabilitySQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems Management Appliance 6.4.120822 through 7.2.101, and K1…EPSS 1.2%8.8CVE-2021-32085Quest kace systems management appliance hard-coded credentials vulnerabilityAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2021-32084), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.