CVE-2021-30116 is a critical credential disclosure vulnerability affecting Kaseya VSA before version 9.5.7, specifically impacting both the VSA agent and server components. An unauthenticated attacker can download a Windows client from the VSA server, extract agent credentials from the KaseyaD.ini file, and then use these to obtain a session ID, bypassing authentication. This vulnerability has a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. It is actively exploited in the wild, notably by ransomware campaigns, and has garnered significant community and media attention, as evidenced by its high EPSS score and numerous articles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.5.0.24CPE matchmatch criteria | cpe:2.3:a:kaseya:vsa_agent:*:*:*:*:*:*:*:* | ||
< 9.5.7aCPE matchmatch criteria | cpe:2.3:a:kaseya:vsa_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.