Vulnerability record · CVE-2015-6922 · published 17 February 2020
CVE-2015-6922: Kaseya VSA authentication bypass allows admin account creation and code execution
Kaseya · Virtual System Administrator
Kaseya Virtual System Administrator (VSA) versions 7.x, 8.x, 9.0 and 9.1 before their respective fixed builds fail to properly require authentication on certain endpoints. A remote attacker can bypass authentication to add an administrative account via LocalAuth/setAccount.aspx or write and execute arbitrary files via the PathData parameter to ConfigTab/uploader.aspx. Because VSA is a remote management platform, compromise gives an attacker broad control over managed endpoints.
Description
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted request to LocalAuth/setAccount.aspx or (2) write to and execute arbitrary files via a full pathname in the PathData parameter to ConfigTab/uploader.aspx.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated remote authentication bypass with public exploit code and very high EPSS on an internet-facing management platform.
What it is
Kaseya Virtual System Administrator (VSA) versions 7.x, 8.x, 9.0 and 9.1 before their respective fixed builds fail to properly require authentication on certain endpoints. A remote attacker can bypass authentication to add an administrative account via LocalAuth/setAccount.aspx or write and execute arbitrary files via the PathData parameter to ConfigTab/uploader.aspx. Because VSA is a remote management platform, compromise gives an attacker broad control over managed endpoints.
Impact
An unauthenticated attacker gains administrative access to the VSA instance and can execute arbitrary code on the server, then leverage VSA's management reach to control managed systems.
Attack surface
Reachable over the network via HTTP requests to the VSA web interface; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Public exploit code is referenced (Packet Storm, Exploit-DB) and EPSS is high at 0.821 (99.6th percentile), though the CVE is not listed in CISA KEV.
What to do
- Upgrade Kaseya VSA to 7.0.0.33, 8.0.0.23, 9.0.0.19, 9.1.0.9 or later fixed builds.
- Restrict network access to the VSA web interface to trusted management networks or VPN only.
- Audit VSA for unexpected administrative accounts and remove any unauthorized ones.
- Review and harden file upload paths and permissions on the VSA server.
- Monitor vendor advisory channels for updated guidance since the linked Kaseya advisory is broken.
Detection
- Monitor web logs for requests to LocalAuth/setAccount.aspx and ConfigTab/uploader.aspx, especially from untrusted sources.
- Alert on creation of new administrative accounts in VSA outside change windows.
- Look for unexpected file writes or process execution originating from the VSA web server.
- Correlate VSA access with outbound management actions to endpoints that were not initiated by known admins.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-6922 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-6922), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.