CVE-2021-30121: (Semi-)Authenticated local file inclusion in Kaseya VSA < v9.5.6
Published Jul 9, 2021
·Updated
Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: https://x.x.x.x/KLC/js/Kaseya.SB.JS/js.aspx?path=C:\Kaseya\WebPages\dl.asp A valid sessionId is required but can be easily obtained via CVE-2021-30118
Affected Software
1 affected component
Kaseya VSA<9.5.6
Remediation
Patch Available
Patch Available
Information
Upgrade to a version above 9.5.6
Event History
Jul 9, 2021
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2021-30121?
CVE-2021-30121 is classified as a medium severity vulnerability.
2
How do I fix CVE-2021-30121?
To mitigate CVE-2021-30121, upgrade Kaseya VSA to a version higher than 9.5.6.
3
What type of vulnerability is CVE-2021-30121?
CVE-2021-30121 is a semi-authenticated local file inclusion vulnerability.
4
What are the prerequisites for exploiting CVE-2021-30121?
Exploiting CVE-2021-30121 requires a valid sessionId, which can be obtained through CVE-2021-30118.
5
What can be affected by CVE-2021-30121?
CVE-2021-30121 can potentially expose arbitrary file contents from the Kaseya VSA application.