{"cvss":9.8,"datePublished":"2022-05-24","dateUpdated":"2022-05-24","description":"ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.","dueDate":"2022-06-14","id":"CVE-2017-18362","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2017-18362","product":"Virtual System/Server Administrator (VSA)","requiredAction":"The impacted product is end-of-life and should be disconnected if still in use.","severity":"CRITICAL","source":"cisa_known_exploited","title":"Kaseya VSA SQL Injection Vulnerability","vendor":"Kaseya"}