CVE-2015-2862: Kaseya Virtual System Administrator
Medium severity, CVSS 4.0. EPSS: 9.5% chance of exploitation in the next 30 days.
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote authenticated users to read arbitrary files via a crafted HTTP request.
Affected products
- Kaseya Virtual System Administrator: from 7.0, before 7.0.0.29 (fixed in 7.0.0.29); from 8.0, before 8.0.0.18 (fixed in 8.0.0.18); from 9.0, before 9.0.0.14 (fixed in 9.0.0.14); from 9.1, before 9.1.0.4 (fixed in 9.1.0.4)
Published 2015-07-20. Last modified 2026-06-17.