An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HConnectwise Automate
APPConnectwise< 2021.0.6.132
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XXE
CWE
Related vulnerabilities
CVE-2025-11492CRITICAL9.6PL ✓same product
ConnectWise Automate Agent – nieszyfrowana komunikacja HTTP podatna na MITM
CVE-2020-15027CRITICAL9.8PL ✓same product
ConnectWise Automate — pominięcie uwierzytelnienia (Auth Bypass)
CVE-2026-6066HIGH7.1same product
ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectW...
CVE-2025-11493HIGH8.8same product
The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, suc...
CVE-2023-47257HIGH8.1same product
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution v...