CVE-2017-18362CISA KEVEPSS p99.7%

CVE-2017-18362Kaseya VSA SQL Injection Vulnerability

Kaseya / Virtual System/Server Administrator (VSA)

Description

ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.

Scoring

EPSS86.71% probability of exploitation · percentile 99.7% · 2026-06-18T12:00:27Z

CISA KEV entry

Added to KEV: 2022-05-24

(incoming)1

TypeTargetConfidenceTier
KEVEntryKaseya VSA SQL Injection Vulnerabilitykev-cve-2017-183620%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Kaseya VSA Remote Code Execution Vulnerability
CVE
Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability
CVE
ConnectWise ScreenConnect Authentication Bypass Vulnerability
CVE
CVE-2025-47178
CVE
Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability
CVE
SonicWall SMA100 SQL Injection Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.