CVE-2021-30116: Kaseya VSA Credential Disclosure Vulnerability Exploitation (CVE-2021-30116)
The short version: Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp. When an attacker downloads a client for Windows and installs it, the file KaseyaD.ini is generated (C:\ProgramFiles (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can be used to log into the affected system. BreachRisk discovers exposed instances from your attack surface and flags this finding so you can prioritize by real-world breach risk.
At a glance
| Fact | Detail |
|---|---|
| Our severity take | High — BreachRisk score 6.9 (impact 4, likelihood 4) |
| CVSS v3.1 (NVD) | Unknown at time of writing |
| In CISA KEV? | Unknown at time of writing — check the KEV catalog |
| Known exploited? | Unknown at time of writing |
| Requires authenticated session? | Unknown at time of writing |
| CVE | CVE-2021-30116, CVE-2021-3116 |
What you need to know
Exposed Kaseya VSA Server appears vulnerable to exploitation of credential disclosure vulnerability (CVE-2021-30116).
- How they find it — internet-facing exposure of the affected product is discoverable by routine scanning.
- How they use it — attackers exploit the vulnerability against reachable instances.
- What it leads to — compromise of the affected service and, depending on placement, a foothold for further movement.
How serious we see it
High — based on BreachRisk impact and likelihood scoring for this threat definition (score 6.9/9). Treat internet-facing instances as priority; confirm exposure and patch status before assuming you're clear.
Recommendations
- Apply security update to exposed Kaseya VSA Server, all versions prior to 9.5.7 are vulnerable.
- If update cannot be immediately completed, restrict access to vulnerable endpoint to internal use only.
How BreachRisk sees it
BreachRisk discovers internet-facing assets tied to this threat, fingerprints the product where possible, and flags exposure for CVE-2021-30116. Where authorized, it can go beyond detection with a bounded, non-disruptive check rather than leaving you with a maybe. Continuous outside-in coverage means the exposed service is already on your radar ranked by how it actually gets used against you.