CVE-2024-1709
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
- Affected products
- Connectwise Screenconnect
- Connectwise Screenconnect
- < 23.9.8
- Fix
- Available
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-288
- NVD status
- Analyzed
- Published
- 2024-02-21
CVE-2024-1709 at NVD
9 known exploits for CVE-2024-1709
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Authentication Bypass Using an Alternate Path or Channel in Connectwise Screenconnect
Exploit for Path Traversal in Connectwise Screenconnect
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
Exploit for Authentication Bypass Using an Alternate Path or Channel in Connectwise Screenconnect
Exploit for Authentication Bypass Using an Alternate Path or Channel in Connectwise Screenconnect
Exploit for Authentication Bypass Using an Alternate Path or Channel in Connectwise Screenconnect
ConnectWise ScreenConnect 23.9.7 Unauthenticated Remote Code Execution
Exploit for Path Traversal in Connectwise Screenconnect
Exploit for Authentication Bypass Using an Alternate Path or Channel in Connectwise Screenconnect