Vulnerabilities > Connectwise > Control

DATE CVE VULNERABILITY TITLE RISK
2023-02-13 CVE-2023-25718 Improper Verification of Cryptographic Signature vulnerability in Connectwise Control 19.3.25270.7185/22.9.10032
In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end user a (different) attacker-controlled executable file.
network
low complexity
connectwise CWE-347
critical
9.8
2023-02-13 CVE-2023-25719 Injection vulnerability in Connectwise Control 19.3.25270.7185
ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWiseControl.Client.exe h parameter.
network
low complexity
connectwise CWE-74
8.8
2020-01-23 CVE-2019-16517 Origin Validation Error vulnerability in Connectwise Control 19.3.25270.7185
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
network
low complexity
connectwise CWE-346
7.5
2020-01-23 CVE-2019-16516 Information Exposure Through Discrepancy vulnerability in Connectwise Control 19.3.25270.7185
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
network
low complexity
connectwise CWE-203
5.0
2020-01-23 CVE-2019-16515 Unspecified vulnerability in Connectwise Control 19.3.25270.7185
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
network
low complexity
connectwise
6.4
2020-01-23 CVE-2019-16514 Unrestricted Upload of File with Dangerous Type vulnerability in Connectwise Control 19.3.25270.7185
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
network
low complexity
connectwise CWE-434
6.5
2020-01-23 CVE-2019-16513 Cross-Site Request Forgery (CSRF) vulnerability in Connectwise Control 19.3.25270.7185
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
6.8
2020-01-23 CVE-2019-16512 Cross-site Scripting vulnerability in Connectwise Control 19.3.25270.7185
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
3.5