Kaseya Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Kaseya products.
Products
- Virtual System/Server Administrator (VSA)4 vulnerabilities
- vsa3 vulnerabilities
- KServer1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2013-10034CRITICAL | Kaseya < 6.3.0.2 uploadImage.asp Arbitrary File Upload RCEAn unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoint allows unauthenticated users to upload files to arbitrary paths via a crafted filename parameter in a multipart/form-data POST request. Due to the lack of authentication and input sanitation, an attacker can upload a file with an .asp extension to a web-accessible directory, which can then be invoked to execute arbitrary code with the privileges of the IUSR account. The vuln… CWE-434Jul 31, 2025 | CVSS9.3v4.0 | EPSS1.84% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-30120CRITICAL | 2FA bypass in Kaseya VSA <= v9.5.6Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, after the user authenticates with username and password, the server sends a response to the client with the booleans MFARequired and MFAEnroled. If the attacker has obtained a password of a user and used an intercepting pro… | CVSS9.9v3.1 | EPSS5.7% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-30119MEDIUM | Authenticated Authenticated reflective XSS in Kaseya VSA <= v9.5.6Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `https://x.x.x.x/HelpDeskTab/rcResults.asp?result=<script>alert(document.cookie)</script>` The same is true for the parameter FileName of /done.asp Eaxmple request: `https://x.x.x.x/done.asp?FileName=";</script><script>alert(1);a="&PathData=&originalName=shell.aspx&Fi… CWE-79Jul 9, 2021 | CVSS5.4v3.1 | EPSS52.7% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-30118CRITICAL | Unauthenticated Remote Code Execution in Kaseya VSA < v9.5.5An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab/uploader.aspx is vulnerable to an unauthenticated arbitrary file upload leading to RCE. An attacker can upload files with the privilege of the Web Server process and subsequently use these files to execute asp commands. Detailed description --- Given the following request: ``` P… | CVSS9.8v3.1 | EPSS60.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-30116CRITICAL | Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can… | CVSS10.0v3.1 | EPSS85.7% | PoCs0 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2017-18362CRITICAL | Kaseya VSA SQL Injection VulnerabilityConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, withou… | CVSS9.8v3.1 | EPSS86.8% | PoCs0 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2018-20753CRITICAL | Kaseya VSA Remote Code Execution VulnerabilityKaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild. Feb 5, 2019 | CVSS9.8v3.1 | EPSS29.3% | PoCs0 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
Kaseya Virtual System/Server Administrator (VSA) URL Redirection to Untrusted Site ('Open Redirect')Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Jul 20, 20151 related artifact | CVSS4.3v2.0 | EPSS10.3% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |