Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
connectwise screenconnect vulnerabilities and exploits
(subscribe to this query)
8.4
CVSSv3
CVE-2024-1708
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
Connectwise Screenconnect
2 Github repositories
8 Articles
10
CVSSv3
CVE-2024-1709
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
Connectwise Screenconnect
4 Github repositories
11 Articles
8.1
CVSSv3
CVE-2023-47257
ConnectWise ScreenConnect up to and including 23.8.4 allows man-in-the-middle malicious users to achieve remote code execution via crafted messages.
Connectwise Screenconnect
Connectwise Automate -
5.5
CVSSv3
CVE-2023-47256
ConnectWise ScreenConnect up to and including 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings
Connectwise Screenconnect
Connectwise Automate -
9.8
CVSSv3
CVE-2023-25718
In ConnectWise Control up to and including 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end user a (different) attacker-c...
Connectwise Control
8.8
CVSSv3
CVE-2023-25719
ConnectWise Control prior to 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWiseControl.Client.exe h parameter. This results in reflected data and injection of malicious code into a downloaded executable. The executa...
Connectwise Control
5.3
CVSSv3
CVE-2022-36781
ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the default configuration. Attackers could exploit this vulnerability to gain unauthorized access by repea...
Connectwise Screenconnect
4.8
CVSSv3
CVE-2019-16512
An issue exists in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is stored XSS in the Appearance modifier.
Connectwise Control 19.3.25270.7185
8.8
CVSSv3
CVE-2019-16513
An issue exists in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests.
Connectwise Control 19.3.25270.7185
6.5
CVSSv3
CVE-2019-16515
An issue exists in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. Certain HTTP security headers are not used.
Connectwise Control 19.3.25270.7185
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
SSRF
buffer overflow
CVE-2023-28952
CVE-2023-41822
CVE-2024-27956
CVE-2023-7028
CVE-2024-34447
CVE-2024-34460
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »