Kaseya VSA용 ConnectWise ManagedITSync integration 2017년까지의 버전은 인증되지 않은 원격 명령에 취약하며, 이를 통해 Kaseya VSA 데이터베이스에 완전한 직접 접근이 가능합니다. 2019년 2월 공격자들은 실제 환경에서 이를 활발히 악용하여 VSA 서버가 관리하는 모든 엔드포인트에 랜섬웨어 페이로드를 다운로드하고 실행했습니다. Kaseya VSA 웹 인터페이스를 통해 ManagedIT.asmx 페이지에 접근할 수 있으면 해당 페이지에 접근할 수 있는 누구나 인증 없이 읽기 및 쓰기를 모두 포함한 임의의 SQL 쿼리를 실행할 수 있습니다.
Kaseya VSA용 ConnectWise ManagedITSync integration 2017년까지의 버전은 인증되지 않은 원격 명령에 취약하며, 이를 통해 Kaseya VSA 데이터베이스에 완전한 직접 접근이 가능합니다. 2019년 2월 공격자들은 실제 환경에서 이를 활발히 악용하여 VSA 서버가 관리하는 모든 엔드포인트에 랜섬웨어 페이로드를 다운로드하고 실행했습니다. Kaseya VSA 웹 인터페이스를 통해 ManagedIT.asmx 페이지에 접근할 수 있으면 해당 페이지에 접근할 수 있는 누구나 인증 없이 읽기 및 쓰기를 모두 포함한 임의의 SQL 쿼리를 실행할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.