CVE-2021-30120
Last modified
CVE-2021-30120 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. EPSS estimates a 5.70% chance of exploitation in the next 30 days.
Description
Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, after the user authenticates with username and password, the server sends a response to the client with the booleans MFARequired and MFAEnroled. If the attacker has obtained a password of a user and used an intercepting proxy (e.g. Burp Suite) to change the value of MFARequered from True to False, there is no prompt for the second factor, but the user is still logged in.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kaseya | Vsa | <= 9.5.6 |
References
- https://csirt.divd.nl/2021/07/07/Kaseya-Limited-Disclosure/Patch, Third Party Advisory
- https://csrit.divd.nl/CVE-2021-30120Permissions Required, Third Party Advisory
- https://csrit.divd.nl/DIVD-2021-00011Permissions Required, Third Party Advisory
- https://csirt.divd.nl/2021/07/07/Kaseya-Limited-Disclosure/Patch, Third Party Advisory
- https://csrit.divd.nl/CVE-2021-30120Permissions Required, Third Party Advisory
- https://csrit.divd.nl/DIVD-2021-00011Permissions Required, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-30120?
How severe is CVE-2021-30120?
How do I fix CVE-2021-30120?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-30114Web-School ERP V 5.0 contains a cross-site request forgery (…6.5
- CVE-2021-30116Kaseya VSA before 9.5.7 allows credential disclosure, as exp…9.8
- CVE-2021-30117The API call /InstallTab/exportFldr.asp is vulnerable to a s…8.8
- CVE-2021-30118An attacker can upload files with the privilege of the Web S…9.8
- CVE-2021-30119Authenticated reflective XSS in HelpDeskTab/rcResults.asp Th…5.4
- CVE-2021-3012A cross-site scripting (XSS) vulnerability in the Document L…5.4
- CVE-2021-30121Semi-authenticated local file inclusion The contents of arbi…6.5
- CVE-2021-30123FFmpeg <=4.3 contains a buffer overflow vulnerability in lib…8.8
- CVE-2021-30124The unofficial vscode-phpmd (aka PHP Mess Detector) extensio…9.8
- CVE-2021-30125Jamf Pro before 10.28.0 allows XSS related to inventory hist…6.1
- CVE-2021-30126Lightmeter ControlCenter 1.1.0 through 1.5.x before 1.5.1 al…6.5
- CVE-2021-30127TerraMaster F2-210 devices through 2021-04-03 use UPnP to ma…7.3
Are you affected by CVE-2021-30120?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
