Virtual System Administrator

Vendor:

First CVE: Jul 14, 2014 · Active for 12 years

8
Total CVEs
More Total CVEs than 85% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
12.5%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Virtual System Administrator over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2014
12 years ago
Most Recent CVE
Feb 17, 2020
2,349 days ago

CVE Severity & Scoring

Virtual System Administrator8 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (12.5%)
Network4 (50.0%)
Unknown3 (37.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (50.0%)
High1 (12.5%)
Unknown3 (37.5%)
User Interaction
None5 (62.5%)
Unknown3 (37.5%)
Required0 (0.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None4 (50.0%)
Unknown3 (37.5%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allo
Feb 17, 20209.884NOYES
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In Ja
Feb 5, 20199.882YESNO
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.
Feb 13, 20208.838NOYES
Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attacke
Jul 20, 20154.332NOYES
An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An unauthenticated attacker can send
Aug 26, 20197.524NONO
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote a
Jul 20, 20154.024NOYES
It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator agent 9.3.0.11 and earlier tries
Mar 26, 20187.419NONO
kapfa.sys in Kaseya Virtual System Administrator (VSA) 6.5 before 6.5.0.17 and 7.0 before 7.0.0.16 allows local users to cause a denial of service (NULL pointer dereference and app
Jul 14, 20141.710NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
1 CVE
12.5% of CVEs· 97th percentile
Metasploit
1 CVE
12.5% of CVEs· 97th percentile
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
4 CVEs
50.0% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Virtual System Administrator

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.011.70.3%00
6.511.70.3%00