CRITICAL🇵🇱 Wersja polska

CVE-2021-30120

CVSS 9.9v3.1pub. 2021-07-09upd. 2026-08-14

Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, after the user authenticates with username and password, the server sends a response to the client with the booleans MFARequired and MFAEnroled. If the attacker has obtained a password of a user and used an intercepting proxy (e.g. Burp Suite) to change the value of MFARequered from True to False, there is no prompt for the second factor, but the user is still logged in.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Kaseya Vsa

    APP
    Kaseya
    ≤ 9.5.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-30117CRITICAL9.8PL ✓same product

Kaseya VSA — blind SQL injection w parametrze fldrId (semi-uwierzytelniony)

CVE-2021-30118CRITICAL9.8PL ✓same product

Kaseya VSA — nieuwierzytelniony arbitrary file upload prowadzący do RCE

CVE-2021-30201HIGH7.5same product

The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) en...

CVE-2021-30119MEDIUM5.4same product

Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp i...

CVE-2021-30121MEDIUM6.5same product

Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Examp...