CVE-2021-30120

2FA bypass in Kaseya VSA <= v9.5.6

Description

Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, after the user authenticates with username and password, the server sends a response to the client with the booleans MFARequired and MFAEnroled. If the attacker has obtained a password of a user and used an intercepting proxy (e.g. Burp Suite) to change the value of MFARequered from True to False, there is no prompt for the second factor, but the user is still logged in.

Remediation

Solution:

  • Upgrade to a version above 9.5.6

Category

9.9
CVSS
Severity: Critical
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.12%
Third-Party Advisory divd.nl Third-Party Advisory divd.nl Third-Party Advisory divd.nl
Affected: n/a n/a
Published at:
Updated at:

References

Link Tags
https://csirt.divd.nl/2021/07/07/Kaseya-Limited-Disclosure/ third party advisory patch
https://csrit.divd.nl/DIVD-2021-00011 third party advisory permissions required
https://csrit.divd.nl/CVE-2021-30120 third party advisory permissions required

Frequently Asked Questions

What is the severity of CVE-2021-30120?
CVE-2021-30120 has been scored as a critical severity vulnerability.
How to fix CVE-2021-30120?
To fix CVE-2021-30120: Upgrade to a version above 9.5.6
Is CVE-2021-30120 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2021-30120 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.