kaseya has 4 CVEs on record between 2019 and 2021. The median CVSS is 9.9 (critical), with 3 rated critical. Most affected products: vsa (2), virtual_system_administrator (1), vsa_agent (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 100% vs 1% corpus
- Median CVSS
- 9.9
- Publish → KEV
- —(2)
- Last 90 days
- 0 prev 0
Worst active — by depth score
CVE-2021-30116Critical· 10.0Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021100CVE-2018-20753Critical· 9.8Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices90CVE-2021-30120Critical· 9.9Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement74CVE-2021-30119Medium· 5.4Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `http…58
kaseya vulnerabilities
CVEs affecting kaseya, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2021-30120Critical· 9.9⚠ ExploitedKaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement
Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed de…
CVE-2021-30119Medium· 5.4⚠ ExploitedAuthenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `http…
Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `http…
CVE-2021-30116Critical· 10.0CISA KEVPoCKaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page …
CVE-2018-20753Critical· 9.8CISA KEVKaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerabili…