SOURCE FACT
Kaseya · Virtual System/Server Administrator (VSA)
ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.
Required action
The impacted product is end-of-life and should be disconnected if still in use.
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2017-18362
View source evidence →