← Back to browse · API

CVE-2017-18362

Severity
CRITICAL
CVSS
9.8
EPSS
0.8682
Risk score
94.59
CISA KEV
Yes
PoC
No
Published
2022-05-24
Modified
2022-05-24
First seen
2026-08-07
Aliases
EUVD-2017-9480, GHSA-W35F-W5CG-JQHH
Products
Kaseya:Virtual System/Server Administrator (VSA), n/a:n/a n/a
Sources
euvd EUVD-2017-9480
cisa.gov CVE-2017-18362

Description

ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.

References