Known Vulnerabilities for Vsa by Kaseya
Listed below are 8 of the newest known vulnerabilities associated with "Vsa" by "Kaseya".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-30201 json | The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are inse... | 7.5 - HIGH | 2021-07-09 | 2022-04-29 |
| CVE-2021-30121 json | Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: `ht... | 6.5 - MEDIUM | 2021-07-09 | 2022-04-29 |
| CVE-2021-30120 json | Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce cli... | 7.5 - HIGH | 2021-07-09 | 2022-07-12 |
| CVE-2021-30119 json | Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely re... | 5.4 - MEDIUM | 2021-07-09 | 2022-04-29 |
| CVE-2021-30118 json | An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Manageme... | 9.8 - CRITICAL | 2021-07-09 | 2022-04-29 |
| CVE-2021-30117 json | The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parame... | 8.8 - HIGH | 2021-07-09 | 2022-04-29 |
| CVE-2021-30116 json | Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise... | 9.8 - CRITICAL | 2021-07-09 | 2023-10-23 |
| CVE-2019-14510 json | An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature creat... | 6.7 - MEDIUM | 2019-10-11 | 2021-07-21 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kaseya | Vsa | 9.5.0.9 | |||
| Application | Kaseya | Vsa | 9.5.0.8 | |||
| Application | Kaseya | Vsa | 9.5.0.23 | |||
| Application | Kaseya | Vsa | 9.5.0.22 | |||
| Application | Kaseya | Vsa | 9.5.0.21 | |||
| Application | Kaseya | Vsa | 9.5.0.20 | |||
| Application | Kaseya | Vsa | 9.5.0.19 | |||
| Application | Kaseya | Vsa | 9.5.0.18 | |||
| Application | Kaseya | Vsa | 9.5.0.17 | |||
| Application | Kaseya | Vsa | 9.5.0.16 | |||
| Application | Kaseya | Vsa | 9.5.0.15 | |||
| Application | Kaseya | Vsa | 9.5.0.14 | |||
| Application | Kaseya | Vsa | 9.5.0.12 | |||
| Application | Kaseya | Vsa | 9.5.0.11 | |||
| Application | Kaseya | Vsa | 9.5.0.10 | |||
| Application | Kaseya | Vsa | 9.1.0.11 | |||
| Application | Kaseya | Vsa | 9.1.0.10 |