Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
n/a n/a — Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .8573 99.7 YES
AFFECTED
Product Versions Fixed
n/a n/a – —
TIMELINE
Apr 2 Reserved by mitre
Nov 3 Added to CISA KEV, remediation due 2021-11-17
Nov 3 Published (CNA: mitre)
Aug 14 EXPLOIT PUBLISHED — CVE-2021-30116. Public exploit reference added.
Aug 14 RESCORED — CVE-2021-30116. CVSS 10 → 9.8 (NVD).
Description
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can be used to log in on dl.asp (https://x.x.x.x/dl.asp?un=840997037507813&pw=113cc622839a4077a84837485ced6b93e440bf66d44057713cb2f95e503a06d9) This request authenticates the client and returns a sessionId cookie that can be used in subsequent attacks to bypass authentication. Security issues discovered --- * Unauthenticated download page leaks credentials * Credentials of agent software can be used to obtain a sessionId (cookie) that can be used for services not intended for use by agents * dl.asp accepts credentials via a GET request * Access to KaseyaD.ini gives an attacker access to sufficient information to penetrate the Kaseya installation and its clients. Impact --- Via the page /dl.asp enough information can be obtained to give an attacker a sessionId that can be used to execute further (semi-authenticated) attacks against the system.
Lifecycle
Complete event history — 5 events, chronological
| Date | Event | Detail |
| April 2, 2021 | Reserved | Reserved by mitre |
| November 3, 2021 | KEV ADDED | Added to CISA KEV, remediation due 2021-11-17 |
| November 3, 2021 | Published | Published (CNA: mitre) |
| August 14, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2021-30116. Public exploit reference added. |
| August 14, 2026 | RESCORED | RESCORED — CVE-2021-30116. CVSS 10 → 9.8 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| n/a | n/a | — | n/a | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2021-30116 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.