W wersjach ScreenConnect™ wcześniejszych niż 26.2, nieprawidłowa walidacja danych wejściowych w funkcji tworzenia Host Pass umożliwiła uwierzytelnionemu użytkownikowi z uprawnieniami do tworzenia Host Pass określenie czasu wygaśnięcia tokena poza zamierzoną maksymalną wartość podczas generowania delegowanych tokenów dostępu.
▸ Pokaż oryginał (EN)
In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:LConnectwise Screenconnect
APPConnectwise< 26.2.2.9585
Powiązane podatności
Authentication Bypass w ConnectWise ScreenConnect — bezpośredni dostęp do systemów
ConnectWise ScreenConnect — instalacja niezaufanych rozszerzeń z RCE
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. AS...
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an at...
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution v...