HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-47257

CVSS 8.1v3.1pub. 2024-02-01upd. 2025-05-07

ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Connectwise Automate

    APP
    Connectwise
    all versions
  • Connectwise Screenconnect

    APP
    Connectwise
    < 23.8.5
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-1709CRITICAL10.0⚠ KEVPL ✓same product

Authentication Bypass w ConnectWise ScreenConnect — bezpośredni dostęp do systemów

CVE-2025-14265CRITICAL9.1PL ✓same product

ConnectWise ScreenConnect — instalacja niezaufanych rozszerzeń z RCE

CVE-2025-11492CRITICAL9.6PL ✓same product

ConnectWise Automate Agent – nieszyfrowana komunikacja HTTP podatna na MITM

CVE-2021-35066CRITICAL9.8PL ✓same product

XXE w ConnectWise Automate umożliwia przejęcie kontroli nad systemem

CVE-2020-15027CRITICAL9.8PL ✓same product

ConnectWise Automate — pominięcie uwierzytelnienia (Auth Bypass)