Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
connectwise automate - vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-47256
ConnectWise ScreenConnect up to and including 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings
Connectwise Screenconnect
Connectwise Automate -
NA
CVE-2023-47257
ConnectWise ScreenConnect up to and including 23.8.4 allows man-in-the-middle malicious users to achieve remote code execution via crafted messages.
Connectwise Screenconnect
Connectwise Automate -
NA
CVE-2023-22518
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated malicious user to reset Confluence and create a Confluence instance administrator account. Using this account, an ...
Atlassian Confluence Data Center
Atlassian Confluence Data Center 8.6.0
Atlassian Confluence Server
Atlassian Confluence Server 8.6.0
1 Metasploit module
11 Github repositories
4 Articles
NA
CVE-2023-23130
Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP...
Connectwise Automate 2022.11
1 Github repository
NA
CVE-2023-23126
Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.
Connectwise Automate 2022.11
1 Github repository
7.5
CVSSv2
CVE-2021-35066
An XXE vulnerability exists in ConnectWise Automate prior to 2021.0.6.132.
Connectwise Automate
5
CVSSv2
CVE-2021-32582
An issue exists in ConnectWise Automate prior to 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an malicious user to extract database information or administrative credentials from an instance via crafted monitor status re...
Connectwise Connectwise Automate
6.5
CVSSv2
CVE-2020-15838
The Agent Update System in ConnectWise Automate prior to 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
Connectwise Automate
7.5
CVSSv2
CVE-2020-15027
ConnectWise Automate up to and including 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.
Connectwise Automate
6
CVSSv2
CVE-2020-15008
A SQLi exists in the probe code of all Connectwise Automate versions prior to 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement an...
Connectwise Connectwise Automate 2019.12
Connectwise Connectwise Automate
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-25525
CVE-2024-4652
CVE-2024-1438
CVE-2024-4671
CVE-2024-34351
arbitrary
CVE-2024-4650
SQL injection
overflow
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »