V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2024-1709
CVE
Critical KEVConfirmedExploit available

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which…

CVSS
10.0
Critical
EPSS
0.94
p99
Published
2024-01-01
Updated
2024-02-22
Description

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

Tags · CWE
KEVPre-authAuth bypass
CWE-288
CAPEC-127
CAPEC-665
Affected products
Screenconnect < 23.9.8
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Timeline
2024-01-01
Published
2024-02-22
Added to KEV
2024-02-22
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.944 · p99
Known exploited (KEV)
Yes
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-127 · CWE-288
└ via CAPEC-665 · CWE-288
└ via CAPEC-665 · CWE-288
└ via CAPEC-665 · CWE-288
Known exploits — Сканер-ВС
CVE-2024-1709
github-poc · https://github.com/AhmedMansour93/Event-ID-229-Rule-Name-SOC262-CVE-2024-1709-
Enterprise
Affected software
ProductVendorStatus
screenconnect*Exploited
Source databases
CVE
Related vulnerabilities