Showing 3 vulnerabilities on this page for vsa

Signals CISA KEV Ransomware Nuclei
Kaseya vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

2FA bypass in Kaseya VSA <= v9.5.6

Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, after the user authenticates with username and password, the server sends a response to the client with the booleans MFARequired and MFAEnroled. If the attacker has obtained a password of a user and used an intercepting pro

CWE-669CWE-863Jul 9, 2021
CVSS9.9v3.1EPSS5.7%PoCs0SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Authenticated Authenticated reflective XSS in Kaseya VSA <= v9.5.6

Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `https://x.x.x.x/HelpDeskTab/rcResults.asp?result=<script>alert(document.cookie)</script>` The same is true for the parameter FileName of /done.asp Eaxmple request: `https://x.x.x.x/done.asp?FileName=";</script><script>alert(1);a="&PathData=&originalName=shell.aspx&Fi

CWE-79Jul 9, 2021
CVSS5.4v3.1EPSS52.7%PoCs0SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Unauthenticated Remote Code Execution in Kaseya VSA < v9.5.5

An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab/uploader.aspx is vulnerable to an unauthenticated arbitrary file upload leading to RCE. An attacker can upload files with the privilege of the Web Server process and subsequently use these files to execute asp commands. Detailed description --- Given the following request: ``` P

CWE-434Jul 9, 20211 related artifact
CVSS9.8v3.1EPSS60.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX