Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Kaseya/
  3. Kaseya 365 Advanced Threat Protection

Kaseya 365 Advanced Threat Protection

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 32 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

ATP solution for SaaS & email with AI-driven detection & auto-response

by Kaseya · kaseya.com · source ↗

Known CVEs (32)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2013-10034 ↗2025

    An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoint allows unauthenticated users to upload files to arbitrary paths via a crafted…

  • CVE-2025-32874 ↗HIGH 7.52025

    An issue was discovered in Kaseya Rapid Fire Tools Network Detective through 2.0.16.0. A vulnerability exists in the EncryptionUtil class because symmetric encryption is implemented in a deterministic…

  • CVE-2025-32353 ↗HIGH 8.22025

    Kaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the collector.txt configuration file.

  • CVE-2021-40386 ↗CRITICAL 9.82022

    Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.

  • CVE-2021-43044 ↗CRITICAL 9.82021

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.

  • CVE-2021-43043 ↗MEDIUM 6.52021

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing an insecure Sudo rule.

  • CVE-2021-43042 ↗CRITICAL 9.82021

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploitable by a remote unauthenticated attacker.

  • CVE-2021-43041 ↗HIGH 8.82021

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string vulnerability in the privileged vaultServer application.

  • CVE-2021-43040 ↗HIGH 8.82021

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to create arbitrary writable files, leading to privilege escalation.

  • CVE-2021-43039 ↗MEDIUM 6.52021

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access.

  • CVE-2021-43038 ↗HIGH 8.82021

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation …

  • CVE-2021-43037 ↗HIGH 7.82021

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This al…

  • CVE-2021-43036 ↗CRITICAL 9.82021

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.

  • CVE-2021-43035 ↗CRITICAL 9.82021

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and execute…

  • CVE-2021-43034 ↗HIGH 7.82021

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as the user apache, leading to privilege escalation.

  • CVE-2021-43033 ↗CRITICAL 9.82021

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. The vulnerability was…

  • CVE-2021-40387 ↗HIGH 8.82021

    An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is authenticated remote code execution.

  • CVE-2021-40385 ↗HIGH 8.82021

    An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is a privilege escalation from read-only user to admin.

  • CVE-2021-30201 ↗HIGH 7.52021

    The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fetched by the system and returned to the attacker. De…

  • CVE-2021-30120 ↗CRITICAL 9.92021

    Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Th…

  • …and 12 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Email Security products

see all →
  • AI Security Mailbox · Abnormal Security
  • AI-Powered Email Security & DMARC Protection · EmailInspect
  • Abnormal AI Security Mailbox · Abnormal Security
  • Abnormal Inbound Email Security · Abnormal Security
  • Abusix Email Threat Protection · Abusix
  • Abusix Guardian Mail · Abusix
  • Account Takeover Protection · Abnormal Security
  • AegisAI Agentic Email Security · AegisAI