Junglewise Threat Intelligence

CVE-2021-30116: Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability

CVE-2021-30116 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Kaseya Server Administrator (VSA), Kaseya Virtual System. Vendors: Kaseya.

Executive brief

Kaseya VSA allows unauthenticated credential disclosure via a default download page. Attackers can obtain Agent_Guid and AgentPassword from generated configuration files to acquire a sessionId cookie, enabling authentication bypass and further attacks.

Affected products

  • Kaseya VSA before 9.5.7

Timeline

  • 2021-07-02: advisory: Vendor advisory published by Kaseya
  • 2021-07-04: disclosed: DIVD case update published
  • 2021-07-01: exploited: Exploited in the wild in July 2021 according to NVD description
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats