Vulnerabilities > Connectwise

DATE CVE VULNERABILITY TITLE RISK
2024-02-21 CVE-2024-1708 Path Traversal vulnerability in Connectwise Screenconnect 22.7/23.8.4/23.8.5
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
network
low complexity
connectwise CWE-22
8.4
2024-02-21 CVE-2024-1709 Unspecified vulnerability in Connectwise Screenconnect 22.7/23.8.4/23.8.5
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
network
low complexity
connectwise
critical
10.0
2024-02-01 CVE-2023-47256 Improper Authentication vulnerability in Connectwise Automate and Screenconnect
ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings
local
low complexity
connectwise CWE-287
5.5
2024-02-01 CVE-2023-47257 Code Injection vulnerability in Connectwise Automate and Screenconnect
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
network
high complexity
connectwise CWE-94
8.1
2023-02-13 CVE-2023-25718 Improper Verification of Cryptographic Signature vulnerability in Connectwise Control 19.3.25270.7185/22.9.10032
In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end user a (different) attacker-controlled executable file.
network
low complexity
connectwise CWE-347
critical
9.8
2023-02-13 CVE-2023-25719 Injection vulnerability in Connectwise Control 19.3.25270.7185/22.9.10032
ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWiseControl.Client.exe h parameter.
network
low complexity
connectwise CWE-74
8.8
2023-02-01 CVE-2023-23126 Improper Restriction of Rendered UI Layers or Frames vulnerability in Connectwise Automate 2022.11
Connectwise Automate 2022.11 is vulnerable to Clickjacking.
network
low complexity
connectwise CWE-1021
6.1
2023-02-01 CVE-2023-23127 Missing Encryption of Sensitive Data vulnerability in Connectwise 22.8.10013.8329
In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS.
network
high complexity
connectwise CWE-311
5.3
2023-02-01 CVE-2023-23128 Unspecified vulnerability in Connectwise 22.8.10013.8329
Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS).
network
low complexity
connectwise
6.1
2023-02-01 CVE-2023-23130 Cleartext Transmission of Sensitive Information vulnerability in Connectwise Automate 2022.11
Connectwise Automate 2022.11 is vulnerable to Cleartext authentication.
network
high complexity
connectwise CWE-319
5.9