CVE-2015-6589
high · 8.8Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary files due to insufficient restrictions in file paths to json.ashx.
8.8
CVSS
13.6%
EPSS (exploit prob.)
96th
EPSS percentile
2020-02-13
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| kaseya | virtual_system_administrator | >= 7.0.0.0, < 7.0.0.33 |
| kaseya | virtual_system_administrator | >= 8.0.0.0, < 8.0.0.23 |
| kaseya | virtual_system_administrator | >= 9.0.0.0, < 9.0.0.19 |
| kaseya | virtual_system_administrator | >= 9.1.0.0, < 9.1.0.9 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/133782/Kaseya-Virtual-System-Administrator-Code-Execution-Privilege-Escalation.html
- http://www.zerodayinitiative.com/advisories/ZDI-15-450
- https://www.exploit-db.com/exploits/38351/
- https://www.securityfocus.com/bid/76838
- http://packetstormsecurity.com/files/133782/Kaseya-Virtual-System-Administrator-Code-Execution-Privilege-Escalation.html
- http://www.zerodayinitiative.com/advisories/ZDI-15-450
- https://www.exploit-db.com/exploits/38351/
- https://www.securityfocus.com/bid/76838
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-6589