Umbra Wiki cve cve/CVE-2017-18362
Back to wiki

CVE-2017-18362 — Kaseya VSA SQL Injection Vulnerability

provenance: imported · CVE: CVE-2017-18362

CVE-2017-18362: Kaseya VSA SQL Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Kaseya
Product Virtual System/Server Administrator (VSA)
Date added 2022-05-24
Due date 2022-06-14
Ransomware campaign use Known

Description

ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.

Required action (CISA)

The impacted product is end-of-life and should be disconnected if still in use.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2017-18362

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2017-18362
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog