CVE-2018-20753Critical· 9.8▾ Hadal⚠ Exploited in the wildKaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerabili…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 5.9 · exploitation 25 · ransomware 5
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due May 4, 2022
Last analysed / modified upstream
29%
Added to the CISA catalog on Apr 13, 2022. Federal remediation due May 4, 2022. View catalog ↗
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.
virtual_system_administrator >= 9.3, < 9.3.0.35virtual_system_administrator >= 9.4, < 9.4.0.36virtual_system_administrator >= 9.5, < 9.5.0.5Upgrade past the affected range:
virtual_system_administrator 9.5.0.5Connected by shared product, vendor, weakness, or advisory.
CVE-2021-30116Critical· 10.0Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021
CVE-2021-30120Critical· 9.9Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement
CVE-2021-30119Medium· 5.4Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `http…