5.9
CVSSv3

CVE-2023-23130

Published: 01/02/2023 Updated: 11/04/2024
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP (rather than HTTPS) during troubleshooting.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

connectwise automate 2022.11

Github Repositories

CVE-2023-23130

CVE-2023-23130 CVE-2023-23130 Connectwise Automate v202211 is vulnerable to Cleartext authentication Authentication is being done via HTTP (cleartext) with SSL disabled