Skip to content

CVE-2021-30116

Insufficiently Protected Credentials: Is CVE-2021-30116 real, exploitable, or a false positive? Here's the community verdict.

signals

public sources

Exploited in wild
Yes
CISA KEV
Public exploit
None known
Metasploit/EDB/PoC
Base severity
10 Critical
CVSS
Exploitation prob.
86%
FIRST EPSS
Weakness
CWE-522 · Insufficiently Protected Credentials
CWE

Confirmed exploited in the wild. Patch this first, regardless of the base score.

baseline read

auto · not a community verdict

Real — exploited in the wild

CISA confirms active exploitation. Treat scanner hits as true positives unless your specific version or config is unaffected.

Based on CISA KEV

Confirm or dispute →

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can be used to log in on dl.asp (https://x.x.x.x/dl.asp?un=840997037507813&pw=113cc622839a4077a84837485ced6b93e440bf66d44057713cb2f95e503a06d9) This request authenticates the client and returns a sessionId cookie that can be used in subsequent attacks to bypass authentication. Security issues discovered --- * Unauthenticated download page leaks credentials * Credentials of agent software can be used to obtain a sessionId (cookie) that can be used for services not intended for use by agents * dl.asp accepts credentials via a GET request * Access to KaseyaD.ini gives an attacker access to sufficient information to penetrate the Kaseya installation and its clients. Impact --- Via the page /dl.asp enough information can be obtained to give an attacker a sessionId that can be used to execute further (semi-authenticated) attacks against the system.

Published

Embed this verdict
TruePositive verdict for CVE-2021-30116
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2021-30116/badge.svg)](https://www.truepositive.app/cve/CVE-2021-30116)
HTML
<a href="https://www.truepositive.app/cve/CVE-2021-30116"><img src="https://www.truepositive.app/cve/CVE-2021-30116/badge.svg" alt="TruePositive verdict for CVE-2021-30116"></a>

Live badge that updates automatically as the community verdict changes.

Community ground truth

Be the first practitioner to weigh in

So far this is only TruePositive's editorial baseline from public sources. Add your real-world verdict below — it becomes the signal the next person triaging this relies on.

🥇 The first 50 practitioners to contribute earn a Founding Contributor badge.

In your experience, is this finding real and exploitable?

awaiting field verdicts
Real, but not a risk here
Not a real issue

Curated baseline: TruePositive's read from public sources is Real & exploitable — a starting point, not a community verdict.

No account needed. Anonymous verdicts post as an unverified signal. Log in to make yours verified and earn reputation.

Field notes & remediation

Verdicts are the quick signal. Notes are the evidence and fixes behind them.

  • 0
    Field note · TruePositive EditorialCurated

    This is confirmed exploited in the wild. It is in the CISA KEV catalog, so attackers are actively using it, not just researchers. It is reachable over the network with no authentication and no user interaction, which is the most dangerous profile. Patch this on priority and confirm the fix holds.

  • 0
    Remediation · TruePositive EditorialCurated

    Required action for Kaseya Virtual System/Server Administrator (VSA): Apply updates per vendor instructions. CISA set a federal remediation due date of 2021-11-17. After patching, verify the vulnerable path is no longer reachable before closing the finding.

Add a field note or remediationoptional
Note type

What are you adding?

Markdown supported · minimum 20 characters.

Same weakness: CWE-522 · Insufficiently Protected Credentials.