ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel
vulnerability, which may allow an attacker direct access to confidential information or
critical systems.
References
Configurations
History
22 Feb 2024, 15:18
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:* | |
Summary |
|
|
CWE | NVD-CWE-Other | |
First Time |
Connectwise screenconnect
Connectwise |
|
References | () https://github.com/rapid7/metasploit-framework/pull/18870 - Issue Tracking, Third Party Advisory | |
References | () https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc - Exploit, Third Party Advisory | |
References | () https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit/ - Press/Media Coverage, Third Party Advisory | |
References | () https://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-admins-to-patch-critical-rce-flaw/ - Press/Media Coverage, Third Party Advisory | |
References | () https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 - Vendor Advisory | |
References | () https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/ - Third Party Advisory | |
References | () https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass - Exploit, Third Party Advisory | |
References | () https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2 - Third Party Advisory | |
References | () https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8 - Third Party Advisory | |
References | () https://www.securityweek.com/connectwise-confirms-screenconnect-flaw-under-active-exploitation/ - Press/Media Coverage, Third Party Advisory |
21 Feb 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 Feb 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 Feb 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-21 16:15
Updated : 2024-02-23 02:00
NVD link : CVE-2024-1709
Mitre link : CVE-2024-1709
CVE.ORG link : CVE-2024-1709
JSON object : View
Products Affected
connectwise
- screenconnect
CWE