THREAT OPS › Threat News › [NVD] CVE-2021-30120 (CRITICAL 9.9) — Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, aft
[NVD] CVE-2021-30120 (CRITICAL 9.9) — Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, aft
CVE-2021-30120 CVSS: 9.9 CRITICAL Published: 2021-07-09T14:15:07.903
Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process, after the user authenticates with username and passwo
Indicators of compromise
- CVE-2021-30120cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-30120