CVE-2024-27215

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1709. Reason: This candidate is a duplicate of CVE-2024-1709. Notes: All CVE users should reference CVE-2024-1709 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

21 Feb 2024, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://github.com/rapid7/metasploit-framework/pull/18870', 'source': 'cve@mitre.org'}
  • {'url': 'https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc', 'source': 'cve@mitre.org'}
  • {'url': 'https://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-admins-to-patch-critical-rce-flaw/', 'source': 'cve@mitre.org'}
  • {'url': 'https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8', 'source': 'cve@mitre.org'}
  • {'url': 'https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/', 'source': 'cve@mitre.org'}
  • {'url': 'https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2', 'source': 'cve@mitre.org'}
  • {'url': 'https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8', 'source': 'cve@mitre.org'}
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : unknown
Summary (en) ConnectWise ScreenConnnect before 23.9.8 allows authentication bypass via an alternate path or channel. (en) Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1709. Reason: This candidate is a duplicate of CVE-2024-1709. Notes: All CVE users should reference CVE-2024-1709 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

21 Feb 2024, 17:15

Type Values Removed Values Added
References
  • () https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/ -

21 Feb 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-21 16:15

Updated : 2024-02-21 18:15


NVD link : CVE-2024-27215

Mitre link : CVE-2024-27215

CVE.ORG link : CVE-2024-27215


JSON object : View

Products Affected

No product.

CWE

No CWE.