CVE-2017-18362
Kaseya VSA SQL Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
YesDecision
Descriptions
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.
La integración ConnectWise ManagedITSync, hasta la versión 2017 para Kaseya VSA, es vulnerable a comandos remotos no autenticados que permiten el acceso directo completo a la base de datos de Kaseya VSA. En febrero de 2019, los atacantes se han aprovechado de este hecho "in the wild" de manera activa para descargar y ejecutar cargas útiles en todos los endpoints gestionados por el servidor VSA. Si la página ManagedIT.asmx está disponible mediante la interfaz web de Kaseya VSA, cualquier usuario con acceso a ésta es capaz de ejecutar consultas SQL, tanto de lectura como de escritura, sin autenticarse.
ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-02-04 CVE Reserved
- 2019-02-05 CVE Published
- 2022-05-24 Exploited in Wild
- 2022-06-14 KEV Due Date
- 2024-06-28 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://archive.today/rdkeQ | Third Party Advisory | |
https://webcache.googleusercontent.com/search?q=cache:ZEo8ZRF_iEIJ:https://helpdesk.kaseya.com/hc/en-gb/articles/360022495572-Connectwise-API-Vulnerability+ | Broken Link |
URL | Date | SRC |
---|---|---|
https://github.com/kbni/owlky | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Connectwise Search vendor "Connectwise" | Manageditsync Search vendor "Connectwise" for product "Manageditsync" | <= 2017 Search vendor "Connectwise" for product "Manageditsync" and version " <= 2017" | kaseya_vsa |
Affected
|