PatchSiren cyber security CVE debrief
CVE-2017-18362 Kaseya CVE debrief
CVE-2017-18362 is a SQL injection vulnerability in Kaseya Virtual System/Server Administrator (VSA) that CISA added to the Known Exploited Vulnerabilities catalog. The supplied CISA record says the impacted product is end-of-life, should be disconnected if still in use, and has known ransomware campaign use.
- Vendor
- Kaseya
- Product
- Virtual System/Server Administrator (VSA)
- CVSS
- CRITICAL 9.8
- CISA KEV
- Listed
- Original CVE published
- 2022-05-24
- Original CVE updated
- 2022-05-24
- Advisory published
- 2022-05-24
- Advisory updated
- 2022-05-24
Who should care
Kaseya VSA administrators, MSPs using VSA, incident responders, and asset owners responsible for legacy remote-management systems should treat this as urgent. Organizations that still have any VSA footprint should verify whether it is exposed or still connected to production networks.
Technical summary
The available source corpus identifies the issue as a SQL injection vulnerability affecting Kaseya VSA. CISA’s KEV entry marks it as known exploited, notes known ransomware campaign use, and indicates the impacted product is end-of-life. No CVSS score was provided in the supplied data.
Defensive priority
High. Known exploitation plus ransomware association and end-of-life product status make this a priority for immediate inventory, isolation, and retirement actions.
Recommended defensive actions
- Inventory all Kaseya VSA deployments and confirm whether any instance remains active.
- If VSA is still in use, follow the CISA guidance in the KEV record and disconnect the end-of-life product.
- Prioritize removal or replacement of any exposed or legacy VSA installation.
- Review administrative access and monitoring data around any VSA instance for signs of unauthorized activity.
- Use the official CVE and NVD records to confirm current advisory status and any vendor-linked remediation guidance.
Evidence notes
This debrief is based only on the supplied CISA KEV metadata and the official CVE/NVD links. The source record explicitly states: product is end-of-life, should be disconnected if still in use, and known ransomware campaign use is present. No CVSS score was included in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-18362 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-18362
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-18362 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-18362
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.