9.8

CVE-2018-20753

Warnung
Exploit
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KaseyaVirtual System Administrator Version >= 9.3 < 9.3.0.35
KaseyaVirtual System Administrator Version >= 9.4 < 9.4.0.36
KaseyaVirtual System Administrator Version >= 9.5 < 9.5.0.5

13.04.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Kaseya VSA Remote Code Execution Vulnerability

Schwachstelle

Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 37.71% 0.971
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.