CVE-2015-6922
critical · 9.8Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted request to LocalAuth/setAccount.aspx or (2) write to and execute arbitrary files via a full pathname in the PathData parameter to ConfigTab/uploader.aspx.
9.8
CVSS
82.1%
EPSS (exploit prob.)
100th
EPSS percentile
2020-02-17
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-287
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| kaseya | virtual_system_administrator | >= 7.0.0.0, < 7.0.0.33 |
| kaseya | virtual_system_administrator | >= 8.0.0.0, < 8.0.0.23 |
| kaseya | virtual_system_administrator | >= 9.0.0.0, < 9.0.0.19 |
| kaseya | virtual_system_administrator | >= 9.1.0.0, < 9.1.0.9 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/133782/Kaseya-Virtual-System-Administrator-Code-Execution-Privilege-Escalation.html
- http://www.zerodayinitiative.com/advisories/ZDI-15-448
- http://www.zerodayinitiative.com/advisories/ZDI-15-449
- https://helpdesk.kaseya.com/entries/96164487--Kaseya-Security-Advisory
- https://www.exploit-db.com/exploits/38351/
- http://packetstormsecurity.com/files/133782/Kaseya-Virtual-System-Administrator-Code-Execution-Privilege-Escalation.html
- http://www.zerodayinitiative.com/advisories/ZDI-15-448
- http://www.zerodayinitiative.com/advisories/ZDI-15-449
- https://helpdesk.kaseya.com/entries/96164487--Kaseya-Security-Advisory
- https://www.exploit-db.com/exploits/38351/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-6922