CVE-2024-1709
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
Sfruttata attivamente
- Nel catalogo CISA delle vulnerabilità sfruttate dal 22 feb 2024
- Le agenzie federali statunitensi devono correggerla entro il 29 feb 2024 (direttiva BOD 22-01)
- Attaccata 2 giorni prima che la vulnerabilità fosse resa pubblica
- Confermata dai sensori, non solo da segnalazioni
- Usata in campagne ransomware
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Fonte: CISA KEV · 20 ago 2026 19 ago 2026 18 ago 2026 17 ago 2026 16 ago 2026 15 ago 2026
Punteggio CVSS10.0 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HTipo di debolezza (CWE)CWE-288
Vendorconnectwise
Prodotti coinvolti
| Vendor | Prodotto | Versioni |
|---|---|---|
| connectwise | screenconnect | < 23.9.8 |
Articoli correlati
This product uses the NVD API but is not endorsed or certified by the NVD.
