Overview
- Description
- ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
- Source
- 9119a7d8-5eab-497f-8521-727c672e3725
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Known exploits
Data from CISA
- Vulnerability name
- ConnectWise ScreenConnect Authentication Bypass Vulnerability
- Exploit added on
- Feb 22, 2024
- Exploit action due
- Feb 29, 2024
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
- 9119a7d8-5eab-497f-8521-727c672e3725
- CWE-288
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "26FEBC12-2B0F-4F8F-BCB8-03683D71B37F", "versionEndExcluding": "23.9.8" } ], "operator": "OR" } ] } ]