Junglewise Threat Intelligence

CVE-2024-1709: ConnectWise ScreenConnect Authentication Bypass Vulnerability

CVE-2024-1709 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2024-02-22

Executive brief

ConnectWise ScreenConnect versions 23.9.7 and prior are vulnerable to an authentication bypass using an alternate path or channel. This allows a remote, unauthenticated attacker to gain administrative access, potentially leading to the creation of new administrator accounts and full system compromise.

Affected products

  • ConnectWise ScreenConnect 23.9.7 and prior

Timeline

  • 2024-02-22: disclosed
  • 2024-02-22: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
  • 2024-02-22: advisory: NVD publication date.

Related threats