CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2015-6922

CVSS 9.8v3.1pub. 2020-02-17upd. 2024-11-21

Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted request to LocalAuth/setAccount.aspx or (2) write to and execute arbitrary files via a full pathname in the PathData parameter to ConfigTab/uploader.aspx.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Kaseya Virtual System Administrator

    APP
    Kaseya
    7.0.0.0 – 7.0.0.33 (excl.)8.0.0.0 – 8.0.0.23 (excl.)9.0.0.0 – 9.0.0.19 (excl.)9.1.0.0 – 9.1.0.9 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2018-20753CRITICAL9.8⚠ KEVPL ✓same product

Kaseya VSA RMM — zdalne wykonanie PowerShell payload na zarządzanych urządzeniach

CVE-2015-6589HIGH8.8same product

Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0...

CVE-2019-15506HIGH7.5same product

An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical infor...

CVE-2017-12410HIGH7.4same product

It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition whe...

CVE-2015-2863MEDIUM4.3same product

Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0...