ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HConnectwise Automate
APPConnectwiseall versionsConnectwise Screenconnect
APPConnectwise< 23.8.5
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
Related vulnerabilities
CVE-2024-1709CRITICAL10.0⚠ KEVPL ✓same product
Authentication Bypass w ConnectWise ScreenConnect — bezpośredni dostęp do systemów
CVE-2025-14265CRITICAL9.1PL ✓same product
ConnectWise ScreenConnect — instalacja niezaufanych rozszerzeń z RCE
CVE-2025-11492CRITICAL9.6PL ✓same product
ConnectWise Automate Agent – nieszyfrowana komunikacja HTTP podatna na MITM
CVE-2021-35066CRITICAL9.8PL ✓same product
XXE w ConnectWise Automate umożliwia przejęcie kontroli nad systemem
CVE-2020-15027CRITICAL9.8PL ✓same product
ConnectWise Automate — pominięcie uwierzytelnienia (Auth Bypass)