Disclosure summary
ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.
CISA remediation guidance
The impacted product is end-of-life and should be disconnected if still in use.
Original records & references
PUBLISHED 2022-05-24T00:00:00-04:00
MODIFIED 2022-05-24T00:00:00-04:00
INGESTED 2026-10-06T11:42:58-04:00