boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2021-30116CRITICAL
n/a n/a — Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .8573   99.7   YES
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 2   Reserved by mitre
  Nov 3   Added to CISA KEV, remediation due 2021-11-17
  Nov 3   Published (CNA: mitre)
  Aug 14  EXPLOIT PUBLISHED — CVE-2021-30116. Public exploit reference added.
  Aug 14  RESCORED — CVE-2021-30116. CVSS 10 → 9.8 (NVD).
CWE-522 · CNA: mitre · CVSS v3.1 · 5 references · NVD status: Analyzed · KEV due November 17, 2021

Description

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can be used to log in on dl.asp (https://x.x.x.x/dl.asp?un=840997037507813&pw=113cc622839a4077a84837485ced6b93e440bf66d44057713cb2f95e503a06d9) This request authenticates the client and returns a sessionId cookie that can be used in subsequent attacks to bypass authentication. Security issues discovered --- * Unauthenticated download page leaks credentials * Credentials of agent software can be used to obtain a sessionId (cookie) that can be used for services not intended for use by agents * dl.asp accepts credentials via a GET request * Access to KaseyaD.ini gives an attacker access to sufficient information to penetrate the Kaseya installation and its clients. Impact --- Via the page /dl.asp enough information can be obtained to give an attacker a sessionId that can be used to execute further (semi-authenticated) attacks against the system.

Lifecycle

Complete event history — 5 events, chronological
DateEventDetail
April 2, 2021ReservedReserved by mitre
November 3, 2021KEV ADDEDAdded to CISA KEV, remediation due 2021-11-17
November 3, 2021PublishedPublished (CNA: mitre)
August 14, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2021-30116. Public exploit reference added.
August 14, 2026RESCOREDRESCORED — CVE-2021-30116. CVSS 10 → 9.8 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
n/an/an/a

Weaknesses

CWE-522

References (5)

Related

Authoritative record: CVE-2021-30116 at cve.org

Weaknesses: CWE-522

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2021-30116 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.