Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
connectwise connectwise automate vulnerabilities and exploits
(subscribe to this query)
6
CVSSv2
CVE-2020-15008
A SQLi exists in the probe code of all Connectwise Automate versions prior to 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement an...
Connectwise Connectwise Automate 2019.12
Connectwise Connectwise Automate
5
CVSSv2
CVE-2021-32582
An issue exists in ConnectWise Automate prior to 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an malicious user to extract database information or administrative credentials from an instance via crafted monitor status re...
Connectwise Connectwise Automate
NA
CVE-2023-47257
ConnectWise ScreenConnect up to and including 23.8.4 allows man-in-the-middle malicious users to achieve remote code execution via crafted messages.
Connectwise Screenconnect
Connectwise Automate -
NA
CVE-2023-47256
ConnectWise ScreenConnect up to and including 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings
Connectwise Screenconnect
Connectwise Automate -
7.5
CVSSv2
CVE-2020-15027
ConnectWise Automate up to and including 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.
Connectwise Automate
6.5
CVSSv2
CVE-2020-15838
The Agent Update System in ConnectWise Automate prior to 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
Connectwise Automate
7.5
CVSSv2
CVE-2021-35066
An XXE vulnerability exists in ConnectWise Automate prior to 2021.0.6.132.
Connectwise Automate
NA
CVE-2023-23126
Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.
Connectwise Automate 2022.11
1 Github repository
NA
CVE-2023-23130
Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP...
Connectwise Automate 2022.11
1 Github repository
6.5
CVSSv2
CVE-2020-14159
By using an Automate API in ConnectWise Automate prior to 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions prior to...
Connectwise Automate Api
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5834
CVE-2024-30100
CVE-2024-4577
physical
dos
CVE-2024-30099
CVE-2024-27801
CVE-2024-32146
logic flaw
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »