Vulnerability Description
By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions before 2019.12.337, 2020 before 2020.1.53, 2020.2 before 2020.2.85, 2020.3 before 2020.3.114, 2020.4 before 2020.4.143, and 2020.5 before 2020.5.178.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Connectwise | Automate Api | < 2019.12.337 |
Related Weaknesses (CWE)
References
- https://www.connectwise.com/company/trust#tab1Vendor Advisory
- https://www.connectwise.com/company/trust#tab1Vendor Advisory
FAQ
What is CVE-2020-14159?
CVE-2020-14159 is a vulnerability with a CVSS score of 8.8 (HIGH). By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL ...
How severe is CVE-2020-14159?
CVE-2020-14159 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-14159?
Check the references section above for vendor advisories and patch information. Affected products include: Connectwise Automate Api.