Vulnerability Description
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Connectwise | Screenconnect | < 23.9.8 |
Related Weaknesses (CWE)
References
- https://github.com/rapid7/metasploit-framework/pull/18870Issue TrackingPatchThird Party Advisory
- https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-ExploitThird Party Advisory
- https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-unPress/Media CoverageThird Party Advisory
- https://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-aPress/Media CoverageThird Party Advisory
- https://www.connectwise.com/company/trust/security-bulletins/connectwise-screencVendor Advisory
- https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-Third Party Advisory
- https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenExploitThird Party Advisory
- https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2ExploitThird Party Advisory
- https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screencThird Party Advisory
- https://www.securityweek.com/connectwise-confirms-screenconnect-flaw-under-activPress/Media CoverageThird Party Advisory
- https://github.com/rapid7/metasploit-framework/pull/18870Issue TrackingPatchThird Party Advisory
- https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-ExploitThird Party Advisory
- https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-unPress/Media CoverageThird Party Advisory
- https://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-aPress/Media CoverageThird Party Advisory
- https://www.connectwise.com/company/trust/security-bulletins/connectwise-screencVendor Advisory
FAQ
What is CVE-2024-1709?
CVE-2024-1709 is a vulnerability with a CVSS score of 10.0 (CRITICAL). ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential inform...
How severe is CVE-2024-1709?
CVE-2024-1709 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-1709?
Check the references section above for vendor advisories and patch information. Affected products include: Connectwise Screenconnect.