UNKNOWNKNOWN EXPLOITEDRANSOMWARE: KNOWN
CVE-2017-18362
Kaseya VSA SQL Injection Vulnerability
Summary
ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.
References
Includes data from the CISA Known Exploited Vulnerabilities catalog.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.