ConnectWise ScreenConnect <= 23.9.7 - Path Traversal
ConnectWise ScreenConnect 23.9.7 and prior contain a path traversal caused by improper handling of user input, letting attackers execute remote code or access confidential data, exploit requires network access. References: https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1708 https://nvd.nist.gov/vuln/detail/CVE-2024-1708 Remediation: Update to the latest version of ConnectWise ScreenConnect.
Used 9 times · 1 assets checked · domain, subdomain, ipv4