THREATOPS
THREAT OPSThreat News › [NVD] CVE-2021-30120 (CRITICAL 9.9) — Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, aft

[NVD] CVE-2021-30120 (CRITICAL 9.9) — Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, aft

lownvdPublished 2021-07-09

CVE-2021-30120 CVSS: 9.9 CRITICAL Published: 2021-07-09T14:15:07.903

Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, after the user authenticates with username and passwo

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-30120