5.3
CVSSv3

CVE-2023-23127

Published: 01/02/2023 Updated: 17/05/2024
CVSS v3 Base Score: 5.3 | Impact Score: 3.6 | Exploitability Score: 1.6
VMScore: 0

Vulnerability Summary

In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS. NOTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP (rather than HTTPS) during troubleshooting.

Vulnerable Product Search on Vulmon Subscribe to Product

connectwise connectwise 22.8.10013.8329

Github Repositories

CVE-2023-23127

CVE-2023-23127 CVE-2023-23127 Connectwise Control - Version: 228100138329 The login page does not implement HSTS headers therefore not enforcing HTTPS