Записи ConnectWise
39 опубликованных записей вендора connectwise.
Профиль для исследователя
- Попали в KEV
- 5 · 12,8 %
- С эксплойтом
- 5 · 12,8 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 10,3 %
- Медиана: публикация → KEV
- 38 дн.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-494 Download of Code Without Integrity Check3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-319 Cleartext Transmission of Sensitive Information3
- CWE-201 Insertion of Sensitive Information Into Sent Data2
- CWE-352 Cross-Site Request Forgery (CSRF)2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
39 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2024-1709Готовый эксплойт | Authentication bypass using an alternate path or channelconnectwise · screenconnect · CWE-288 | Критическая10,0 | KEV | 100,0 % | 21 февр. 2024 г. |
95Срочно | CVE-2017-18362Готовый эксплойт | ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct acconnectwise · manageditsync · CWE-89 | Критическая9,8 | KEV | 86,8 % | 5 февр. 2019 г. |
92Срочно | CVE-2024-1708Готовый эксплойт | Improper limitation of a pathname to a restricted directory (“path traversal”)connectwise · screenconnect · CWE-22 | Высокая8,4 | KEV | 95,4 % | 21 февр. 2024 г. |
69На этой неделе | CVE-2026-84869Готовый эксплойт | ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actionsconnectwise · screenconnect · CWE-269 | Критическая9,9 | KEV | 0,9 % | 8 сент. 2026 г. |
59В плане | CVE-2025-3935Готовый эксплойт | ScreenConnect Exposure to ASP.NET ViewState Code Injectionconnectwise · screenconnect · CWE-502 | Высокая7,2 | KEV | 3,5 % | 25 апр. 2025 г. |
39Наблюдать | CVE-2020-15027Эксплойта нет | ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a seriesconnectwise · automate · CWE-287 | Критическая9,8 | — | 1,3 % | 16 июл. 2020 г. |
39Наблюдать | CVE-2019-16517Эксплойта нет | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-346 | Критическая9,8 | — | 1,3 % | 23 янв. 2020 г. |
39Наблюдать | CVE-2021-35066Эксплойта нет | An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.connectwise · automate · CWE-611 | Критическая9,8 | — | 1,1 % | 21 июн. 2021 г. |
39Наблюдать | CVE-2023-25718Эксплойта нет | In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions canconnectwise · control · CWE-347 | Критическая9,8 | — | 0,7 % | 13 февр. 2023 г. |
36Наблюдать | CVE-2020-14159Эксплойта нет | By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications connectwise · automate api · CWE-89 | Высокая8,8 | — | 1,9 % | 15 июн. 2020 г. |
36Наблюдать | CVE-2025-14265Эксплойта нет | Improper server-side validation in ScreenConnect extension frameworkconnectwise · screenconnect · CWE-494 | Критическая9,1 | — | 0,4 % | 11 дек. 2025 г. |
35Наблюдать | CVE-2020-15838Эксплойта нет | The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.connectwise · automate · CWE-732 | Высокая8,8 | — | 1,2 % | 9 окт. 2020 г. |
35Наблюдать | CVE-2023-25719Эксплойта нет | ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWiconnectwise · control · CWE-74 | Высокая8,8 | — | 1,1 % | 13 февр. 2023 г. |
35Наблюдать | CVE-2019-16513Эксплойта нет | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-352 | Высокая8,8 | — | 1,0 % | 23 янв. 2020 г. |
35Наблюдать | CVE-2017-11726Эксплойта нет | services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstrconnectwise · manage · CWE-352 | Высокая8,8 | — | 0,5 % | 31 июл. 2017 г. |
35Наблюдать | CVE-2026-9089Эксплойта нет | The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operatioconnectwise · automate · CWE-494 | Высокая8,8 | — | 0,2 % | 21 мая 2026 г. |
32Наблюдать | CVE-2023-47257Эксплойта нет | ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.connectwise · automate · CWE-94 | Высокая8,1 | — | 1,0 % | 1 февр. 2024 г. |
30Наблюдать | CVE-2021-32582Эксплойта нет | An issue was discovered in ConnectWise Automate before 2021.5.connectwise · connectwise automate · CWE-89 | Высокая7,5 | — | 1,1 % | 17 июн. 2021 г. |
30Наблюдать | CVE-2020-15008Эксплойта нет | A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12.connectwise · connectwise automate · CWE-89 | Высокая7,5 | — | 0,9 % | 7 июл. 2020 г. |
30Наблюдать | CVE-2025-11493Эксплойта нет | Self-Update Verification Mechanism Process in ConnectWise Automateconnectwise · automate · CWE-494 | Высокая7,5 | — | 0,2 % | 16 окт. 2025 г. |
30Наблюдать | CVE-2025-11492Proof of concept | HTTP Configuration and Encryption in Transitconnectwise · automate · CWE-319 | Высокая7,5 | — | 0,2 % | 16 окт. 2025 г. |
29Наблюдать | CVE-2019-16514Эксплойта нет | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-434 | Высокая7,2 | — | 4,2 % | 23 янв. 2020 г. |
28Наблюдать | CVE-2026-6066Эксплойта нет | Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Centerconnectwise · automate · CWE-319 | Высокая7,1 | — | 0,1 % | 20 апр. 2026 г. |
27Наблюдать | CVE-2019-16516Proof of concept | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-203 | Средняя5,3 | — | 19,1 % | 23 янв. 2020 г. |
27Наблюдать | CVE-2019-16515Эксплойта нет | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control | Средняя6,5 | — | 1,7 % | 23 янв. 2020 г. |
- CVE-2024-1709100Срочно
Authentication bypass using an alternate path or channel
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %connectwise · screenconnect21 февр. 2024 г.
- CVE-2017-1836295Срочно
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct ac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %connectwise · manageditsync5 февр. 2019 г.
- CVE-2024-170892Срочно
Improper limitation of a pathname to a restricted directory (“path traversal”)
ВысокаяCVSS 8,4KEVГотовый эксплойтEPSS 95 %connectwise · screenconnect21 февр. 2024 г.
- CVE-2026-8486969На этой неделе
ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 1 %connectwise · screenconnect8 сент. 2026 г.
- CVE-2025-393559В плане
ScreenConnect Exposure to ASP.NET ViewState Code Injection
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 4 %connectwise · screenconnect25 апр. 2025 г.
- CVE-2020-1502739Наблюдать
ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %connectwise · automate16 июл. 2020 г.
- CVE-2019-1651739Наблюдать
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %connectwise · control23 янв. 2020 г.
- CVE-2021-3506639Наблюдать
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %connectwise · automate21 июн. 2021 г.
- CVE-2023-2571839Наблюдать
In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %connectwise · control13 февр. 2023 г.
- CVE-2020-1415936Наблюдать
By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %connectwise · automate api15 июн. 2020 г.
- CVE-2025-1426536Наблюдать
Improper server-side validation in ScreenConnect extension framework
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %connectwise · screenconnect11 дек. 2025 г.
- CVE-2020-1583835Наблюдать
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %connectwise · automate9 окт. 2020 г.
- CVE-2023-2571935Наблюдать
ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %connectwise · control13 февр. 2023 г.
- CVE-2019-1651335Наблюдать
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %connectwise · control23 янв. 2020 г.
- CVE-2017-1172635Наблюдать
services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstr
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %connectwise · manage31 июл. 2017 г.
- CVE-2026-908935Наблюдать
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operatio
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %connectwise · automate21 мая 2026 г.
- CVE-2023-4725732Наблюдать
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %connectwise · automate1 февр. 2024 г.
- CVE-2021-3258230Наблюдать
An issue was discovered in ConnectWise Automate before 2021.5.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %connectwise · connectwise automate17 июн. 2021 г.
- CVE-2020-1500830Наблюдать
A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %connectwise · connectwise automate7 июл. 2020 г.
- CVE-2025-1149330Наблюдать
Self-Update Verification Mechanism Process in ConnectWise Automate
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %connectwise · automate16 окт. 2025 г.
- CVE-2025-1149230Наблюдать
HTTP Configuration and Encryption in Transit
ВысокаяCVSS 7,5Proof of conceptEPSS 0 %connectwise · automate16 окт. 2025 г.
- CVE-2019-1651429Наблюдать
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
ВысокаяCVSS 7,2Эксплойта нетEPSS 4 %connectwise · control23 янв. 2020 г.
- CVE-2026-606628Наблюдать
Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Center
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %connectwise · automate20 апр. 2026 г.
- CVE-2019-1651627Наблюдать
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
СредняяCVSS 5,3Proof of conceptEPSS 19 %connectwise · control23 янв. 2020 г.
- CVE-2019-1651527Наблюдать
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %connectwise · control23 янв. 2020 г.