CVE CVE

CVE-2024-1709

CISA Known Exploited Vulnerability (KEV)

ConnectWise ScreenConnect Authentication Bypass Vulnerability

February 22, 2024

February 29, 2024

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel

vulnerability, which may allow an attacker direct access to confidential information or

critical systems.

Weakness Enumeration

CWE-ID CWE Name

CWE-288
Authentication Bypass Using an Alternate Path or Channel

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
10
Severity:

CRITICAL

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS v2

Not defined