CVE-2015-6922
Summary
| CVE | CVE-2015-6922 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-17 18:15:00 UTC |
| Updated | 2020-02-26 15:21:00 UTC |
| Description | Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted request to LocalAuth/setAccount.aspx or (2) write to and execute arbitrary files via a full pathname in the PathData parameter to ConfigTab/uploader.aspx. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kaseya | Virtual System Administrator | All | All | All | All |
| Application | Kaseya | Virtual System Administrator | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Kaseya Virtual System Administrator Code Execution / Privilege Escalation ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (2) - ASP webapps Exploit | MISC | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Zero Day Initiative | MISC | www.zerodayinitiative.com | Third Party Advisory, VDB Entry |
| Zero Day Initiative | MISC | www.zerodayinitiative.com | Third Party Advisory, VDB Entry |
| Kaseya Security Advisory : Kaseya | MISC | helpdesk.kaseya.com | Broken Link, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.