← العودة للجدول
CVE-2015-6922
CVE-2015-6922 — Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.
📅 2020-02-17
🔴 Critical 🔥 No NVD Exploit Vulnerability CVSS 9.8

📋 الوصف الكامل

Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted request to LocalAuth/setAccount.aspx or (2) write to and execute arbitrary files via a full pathname in the PathData paramete

💻 الأنظمة المتأثرة

Kaseya Virtual System

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2015-6922

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2015-6922 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←