CVE-2021-30116This vulnerability is part of CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. It has been observed in ransomware campaigns.
Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.
Kaseya
Virtual System/Server Administrator (VSA)
See vendor advisoryThis vulnerability was identified in Virtual System/Server Administrator (VSA) by Kaseya. Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.
High - Known ransomware exploitation
Complete system compromise possible
https://nvd.nist.gov/vuln/detail/CVE-2021-30116
Apply updates per vendor instructions.
Due Date: 11/17/2021