Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
connectwise automate - vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2020-15027
ConnectWise Automate up to and including 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.
Connectwise Automate
7.5
CVSSv3
CVE-2020-15008
A SQLi exists in the probe code of all Connectwise Automate versions prior to 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement an...
Connectwise Connectwise Automate 2019.12
Connectwise Connectwise Automate
8.8
CVSSv3
CVE-2020-14159
By using an Automate API in ConnectWise Automate prior to 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions prior to...
Connectwise Automate Api
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2