Executive brief
Kaseya VSA allows unauthenticated credential disclosure via a default download page. Attackers can obtain Agent_Guid and AgentPassword from generated configuration files to acquire a sessionId cookie, enabling authentication bypass and further attacks.
Affected products
- Kaseya VSA before 9.5.7
Timeline
- 2021-07-02: advisory: Vendor advisory published by Kaseya
- 2021-07-04: disclosed: DIVD case update published
- 2021-07-01: exploited: Exploited in the wild in July 2021 according to NVD description
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog