GHSA-wr85-vcm8-q7f4CriticalCVSS 9.8

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API...

Published
July 28, 2026
Last Modified
July 28, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.

🔗 References (4)