HIGH🇵🇱 Wersja polska

CVE-2019-16514

CVSS 7.2v3.1pub. 2020-01-23upd. 2024-11-21

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administrative users could upload an unsigned extension ZIP file containing executable code that is subsequently executed by the server.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Connectwise Control

    APP
    Connectwise
    19.3.25270.7185
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2023-25718CRITICAL9.8PL ✓same product

ConnectWise Control — manipulacja podpisanym plikiem wykonywalnym

CVE-2019-16517CRITICAL9.8PL ✓same product

ConnectWise Control — błędna konfiguracja CORS umożliwia nieautoryzowane działania administracyjne

CVE-2023-25719HIGH8.8same product

ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parame...

CVE-2019-16513HIGH8.8same product

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be ...

CVE-2019-16516MEDIUM5.3same product

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a u...