Virtual System Administrator
Vendor:
First CVE: Jul 14, 2014 · Active for 12 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
12.5%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Virtual System Administrator over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2014
12 years ago
Most Recent CVE
Feb 17, 2020
2,349 days ago
CVE Severity & Scoring
Virtual System Administrator8 CVEs
13%
25%
38%
25%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (12.5%)
Network4 (50.0%)
Unknown3 (37.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (50.0%)
High1 (12.5%)
Unknown3 (37.5%)
User Interaction
None5 (62.5%)
Unknown3 (37.5%)
Required0 (0.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None4 (50.0%)
Unknown3 (37.5%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-6922CRITICAL Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allo | Feb 17, 2020 | 9.8 | 84 | NO | YES |
CVE-2018-20753CRITICAL Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In Ja | Feb 5, 2019 | 9.8 | 82 | YES | NO |
CVE-2015-6589HIGH Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0. | Feb 13, 2020 | 8.8 | 38 | NO | YES |
CVE-2015-2863MEDIUM Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attacke | Jul 20, 2015 | 4.3 | 32 | NO | YES |
CVE-2019-15506HIGH An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An unauthenticated attacker can send | Aug 26, 2019 | 7.5 | 24 | NO | NO |
CVE-2015-2862MEDIUM Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote a | Jul 20, 2015 | 4.0 | 24 | NO | YES |
CVE-2017-12410HIGH It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator agent 9.3.0.11 and earlier tries | Mar 26, 2018 | 7.4 | 19 | NO | NO |
kapfa.sys in Kaseya Virtual System Administrator (VSA) 6.5 before 6.5.0.17 and 7.0 before 7.0.0.16 allows local users to cause a denial of service (NULL pointer dereference and app | Jul 14, 2014 | 1.7 | 10 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
1 CVE
12.5% of CVEs· 97th percentile
Metasploit
1 CVE
12.5% of CVEs· 97th percentile
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
4 CVEs
50.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Virtual System Administrator
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0 | 1 | 1.7 | 0.3% | 0 | 0 |
| 6.5 | 1 | 1.7 | 0.3% | 0 | 0 |