Kaseya Releases Patches for Vulnerabilities Exploited in Ransomware Attack

Kaseya Patches
Share It On:

13th July 2021, Kathmandu

Patches have been released for vulnerabilities exploited in ransomware attacks by Kaseya. A software patch has been released by software vendor Kaseya located in Florida. Critical vulnerabilities were used to target more than 1500 businesses worldwide as part of a supply-chain ransomware attack. The organization had requested customers to shut down their server until the patch is deployed. The fix has been implemented after 10 days for the three flaws.

CVE-2021-30116 – Credentials leak + business logic flaw

CVE-2021-30119 – Cross-site scripting vulnerability

CVE-2021-30120 – Two-factor authentication bypass

The newer version available is VSA version 9.5.7a (9.5.7.2994)

Dutch Institute for Vulnerability Disclosure had been discovered and ethically reported to Kaseya.

The vulnerabilities included SQL injection, remote code execution, local file inclusion, and XML external entity vulnerability, which has now been fixed.

A mandatory password change has been imposed upon the customers by Kaseya, and services are now being restored (more than 60% have been restored already).

Multiple flaws had been chained for the sophisticated attack.


Share It On:

Recent Posts

Garima Bikas Bank Online Payment Service: Secure E-commerce Transactions with Debit and Credit Cards

Garima Bikas Bank Online Payment Service: Secure E-commerce Transactions with

Share It On: 24th January 2025, Kathmandu Garima Bikas Bank has introduced a new e-commerce service for its customers. They

First Microfinance Q2 Results: Net Profit Down 38% Amidst Rising NPLs

First Microfinance Q2 Results: Net Profit Down 38% Amidst Rising

Share It On:24th January 2025, Kathmandu First Microfinance Laghu Bitta Bittiya Sanstha has released its financial results for the second

Best Finance Founder Shares Sale: Exclusive Offer for Existing Shareholders

Best Finance Founder Shares Sale: Exclusive Offer for Existing Shareholders

Share It On:24th January 2025, Kathmandu Best Finance Company Limited has placed 535,927 founder shares up for sale. These shares

NLG Insurance Appoints Noor Prakash Pradhan as Independent Director to Strengthen Corporate Governance

NLG Insurance Appoints Noor Prakash Pradhan as Independent Director to

Share It On:24th January 2025, Kathmandu NLG Insurance has appointed Noor Prakash Pradhan as its Independent Director. The board made

Nepal Economic Recovery: RBB CEO Khanal on Growth, Challenges, and Opportunities

Nepal Economic Recovery: RBB CEO Khanal on Growth, Challenges, and

Share It On:24th January 2025, Kathmandu Devendra Raman Khanal, CEO of Rastriya Banijya Bank, spoke at the bank’s 60th Annual

  • by Mina Aryal
  • January 24, 2025
ChatGPT Down: Global Outage Impacts Users in Nepal & Beyond

ChatGPT Down: Global Outage Impacts Users in Nepal & Beyond

Share It On: 24th January 2025, Kathmandu ChatGPT, the popular AI chatbot developed by OpenAI, experienced a major outage on

  • by Mina Aryal
  • January 24, 2025