Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. T…
Critical CVSS 9.9
Summary
Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, after the user authenticates with username and password, the server sends a response to the client with the booleans MFARequired and MFAEnroled. If the attacker has obtained a password of a user and used an intercepting pr…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://csirt.divd.nl/2021/07/07/Kaseya-Limited-Disclosure/ Patch
- https://csrit.divd.nl/CVE-2021-30120 Permissions Required
- https://csrit.divd.nl/DIVD-2021-00011 Permissions Required
- https://csirt.divd.nl/2021/07/07/Kaseya-Limited-Disclosure/ Patch
- https://csrit.divd.nl/CVE-2021-30120 Permissions Required
- https://csrit.divd.nl/DIVD-2021-00011 Permissions Required
Timeline
- nvd_ingest NVD