Kaseya Vulnerabilities and Affected Products
Vulnerabilities associated with Virtual System/Server Administrator (VSA).
Products
Clear product- Virtual System/Server Administrator (VSA)4 vulnerabilities
- vsa3 vulnerabilities
- KServer1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-30116CRITICAL | Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can… | CVSS10.0v3.1 | EPSS85.7% | PoCs0 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2017-18362CRITICAL | Kaseya VSA SQL Injection VulnerabilityConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, withou… | CVSS9.8v3.1 | EPSS86.8% | PoCs0 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2018-20753CRITICAL | Kaseya VSA Remote Code Execution VulnerabilityKaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild. Feb 5, 2019 | CVSS9.8v3.1 | EPSS29.3% | PoCs0 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
Kaseya Virtual System/Server Administrator (VSA) URL Redirection to Untrusted Site ('Open Redirect')Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Jul 20, 20151 related artifact | CVSS4.3v2.0 | EPSS10.3% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |