
Cloud Vulnerability DB
A community-led vulnerabilities database
Kaseya VSA before version 9.5.7 contained a critical credential disclosure vulnerability (CVE-2021-30116) that was exploited in the wild during July 2021. The vulnerability allowed attackers to obtain credentials through an unauthenticated download page that exposed agent credentials, which could then be used to bypass authentication. This vulnerability was one of several zero-day flaws discovered by researchers at the Dutch Institute for Vulnerability Disclosure (DIVD) and was actively exploited by the REvil ransomware group in a major supply chain attack (DIVD Update, Tenable Blog).
The vulnerability stems from Kaseya VSA's default configuration where the download page (dl.asp) allows clients to be downloaded without authentication. When a Windows client is installed, it generates a KaseyaD.ini file containing an Agent_Guid and AgentPassword. These credentials could be used to authenticate on dl.asp and obtain a sessionId cookie that enabled further attacks. The vulnerability received a CVSS v3.1 score of 9.8 (Critical) from NIST and 10.0 from MITRE, indicating the highest severity level (NVD).
The exploitation of this vulnerability led to one of the largest ransomware attacks on record, affecting approximately 1,500 businesses across 17 countries. Notable impacts included the shutdown of 800 Coop supermarket stores in Sweden, disruption to Swedish railway services, and affected systems in multiple schools and kindergartens in New Zealand. The REvil ransomware group initially demanded a $70 million ransom to provide a universal decryptor for all affected organizations (SecPod Blog).
The vulnerability was actively exploited by the REvil ransomware group as part of a sophisticated supply chain attack. The attackers used the credential disclosure vulnerability along with other zero-day flaws to deploy ransomware through Kaseya's VSA software. The attack was particularly effective because it targeted managed service providers (MSPs), allowing the ransomware to spread to their downstream customers (Tenable Blog).
Kaseya released patch 9.5.7a to address this vulnerability and other related security issues. The company advised all on-premises customers to keep VSA Servers offline until patching was complete. Additional security measures included implementing multi-factor authentication, placing administrative interfaces behind a VPN, and implementing IP allowlisting for remote monitoring and management capabilities (Kaseya Notice).
The incident garnered significant attention from government agencies and security researchers. CISA and the FBI issued joint guidance for affected MSPs and their customers. Kaseya worked closely with security researchers from DIVD, who had previously identified and reported the vulnerability. The company received praise for their cooperative approach to addressing the security issues, though they were ultimately unable to patch the vulnerability before it was exploited (DIVD Update).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."