← Vulnerability feed

Vulnerability record · CVE-2021-30116 · published 9 July 2021

CVE-2021-30116: Kaseya VSA credential disclosure via unauthenticated download page

Kaseya · Vsa Agent

Kaseya VSA before 9.5.7 exposes an unauthenticated download page (dl.asp) that leaks agent credentials and accepts them via GET request. An attacker who obtains the Agent_Guid and AgentPassword from KaseyaD.ini can authenticate to dl.asp and receive a sessionId cookie, enabling semi-authenticated attacks against the VSA server and its managed clients. This flaw was exploited in the wild in July 2021 and is listed in CISA KEV with known ransomware campaign use.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 86% · top 0.3% CWE-522 · Insufficiently protected credentials
9.8CVSS 3.1 base score, v2 7.5
86%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
9References, 2 tagged exploit
14 Aug 2026Last modified by NVD

Description

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can be used to log in on dl.asp (https://x.x.x.x/dl.asp?un=840997037507813&pw=113cc622839a4077a84837485ced6b93e440bf66d44057713cb2f95e503a06d9) This request authenticates the client and returns a sessionId cookie that can be used in subsequent attacks to bypass authentication. Security issues discovered --- * Unauthenticated download page leaks credentials * Credentials of agent software can be used to obtain a sessionId (cookie) that can be used for services not intended for use by agents * dl.asp accepts credentials via a GET request * Access to KaseyaD.ini gives an attacker access to sufficient information to penetrate the Kaseya installation and its clients. Impact --- Via the page /dl.asp enough information can be obtained to give an attacker a sessionId that can be used to execute further (semi-authenticated) attacks against the system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, active in-the-wild exploitation, CISA KEV listing with ransomware use, and EPSS above 0.85 make this an urgent patch-first issue.

What it is

Kaseya VSA before 9.5.7 exposes an unauthenticated download page (dl.asp) that leaks agent credentials and accepts them via GET request. An attacker who obtains the Agent_Guid and AgentPassword from KaseyaD.ini can authenticate to dl.asp and receive a sessionId cookie, enabling semi-authenticated attacks against the VSA server and its managed clients. This flaw was exploited in the wild in July 2021 and is listed in CISA KEV with known ransomware campaign use.

Impact

An attacker gains a valid sessionId that bypasses authentication and can be used to execute further attacks against the Kaseya installation and its clients. The disclosed agent credentials provide sufficient information to penetrate the VSA server and downstream managed endpoints.

Attack surface

Reachable over the network via the default dl.asp URL on on-premise Kaseya VSA; no authentication or user interaction is required (CVSS AV:N/AC:L/PR:N/UI:N). Credentials are accepted via GET request, so a crafted URL alone can yield a sessionId.

Exploitation

Exploited in the wild in July 2021 and added to CISA KEV on 2021-11-03 with known ransomware campaign use; EPSS 30-day probability is 0.857 (99.7th percentile) and references include an Exploit-tagged advisory.

What to do

  • Upgrade Kaseya VSA to 9.5.7 or later per vendor instructions.
  • Restrict network access to dl.asp and the VSA management interface to trusted IPs only.
  • Rotate agent credentials and invalidate existing sessionId cookies after patching.
  • Monitor for and remove unauthorized KaseyaD.ini exposure or agent installs on untrusted hosts.
  • Apply CISA KEV required action and verify no residual compromise before restoring service.

Detection

  • Hunt for GET requests to /dl.asp with un and pw query parameters in web server or proxy logs.
  • Alert on sessionId cookie issuance to requests lacking prior authentication.
  • Monitor for unexpected KaseyaD.ini file reads or agent installations on non-managed hosts.
  • Correlate VSA server logs for semi-authenticated actions following dl.asp access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-30116 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-30116 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2021-30116), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.