Перейти к содержимому
Noroxi

Записи ConnectWise

39 опубликованных записей вендора connectwise.

Профиль для исследователя

Попали в KEV
5 · 12,8 %
С эксплойтом
5 · 12,8 %
Pre-auth RCE
1
С записью об исправлении
10,3 %
Медиана: публикация → KEV
38 дн.

Все записи

39 записей
  • CVE-2024-1709
    100Срочно

    Authentication bypass using an alternate path or channel

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    connectwise · screenconnect21 февр. 2024 г.

  • CVE-2017-18362
    95Срочно

    ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct ac

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %

    connectwise · manageditsync5 февр. 2019 г.

  • CVE-2024-1708
    92Срочно

    Improper limitation of a pathname to a restricted directory (“path traversal”)

    ВысокаяCVSS 8,4KEVГотовый эксплойтEPSS 95 %

    connectwise · screenconnect21 февр. 2024 г.

  • CVE-2026-84869
    69На этой неделе

    ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions

    КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 1 %

    connectwise · screenconnect8 сент. 2026 г.

  • CVE-2025-3935
    59В плане

    ScreenConnect Exposure to ASP.NET ViewState Code Injection

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 4 %

    connectwise · screenconnect25 апр. 2025 г.

  • CVE-2020-15027
    39Наблюдать

    ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    connectwise · automate16 июл. 2020 г.

  • CVE-2019-16517
    39Наблюдать

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    connectwise · control23 янв. 2020 г.

  • CVE-2021-35066
    39Наблюдать

    An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    connectwise · automate21 июн. 2021 г.

  • CVE-2023-25718
    39Наблюдать

    In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    connectwise · control13 февр. 2023 г.

  • CVE-2020-14159
    36Наблюдать

    By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    connectwise · automate api15 июн. 2020 г.

  • CVE-2025-14265
    36Наблюдать

    Improper server-side validation in ScreenConnect extension framework

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    connectwise · screenconnect11 дек. 2025 г.

  • CVE-2020-15838
    35Наблюдать

    The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    connectwise · automate9 окт. 2020 г.

  • CVE-2023-25719
    35Наблюдать

    ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWi

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    connectwise · control13 февр. 2023 г.

  • CVE-2019-16513
    35Наблюдать

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    connectwise · control23 янв. 2020 г.

  • CVE-2017-11726
    35Наблюдать

    services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstr

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    connectwise · manage31 июл. 2017 г.

  • CVE-2026-9089
    35Наблюдать

    The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operatio

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    connectwise · automate21 мая 2026 г.

  • CVE-2023-47257
    32Наблюдать

    ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    connectwise · automate1 февр. 2024 г.

  • CVE-2021-32582
    30Наблюдать

    An issue was discovered in ConnectWise Automate before 2021.5.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    connectwise · connectwise automate17 июн. 2021 г.

  • CVE-2020-15008
    30Наблюдать

    A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    connectwise · connectwise automate7 июл. 2020 г.

  • CVE-2025-11493
    30Наблюдать

    Self-Update Verification Mechanism Process in ConnectWise Automate

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    connectwise · automate16 окт. 2025 г.

  • CVE-2025-11492
    30Наблюдать

    HTTP Configuration and Encryption in Transit

    ВысокаяCVSS 7,5Proof of conceptEPSS 0 %

    connectwise · automate16 окт. 2025 г.

  • CVE-2019-16514
    29Наблюдать

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 4 %

    connectwise · control23 янв. 2020 г.

  • CVE-2026-6066
    28Наблюдать

    Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Center

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    connectwise · automate20 апр. 2026 г.

  • CVE-2019-16516
    27Наблюдать

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    СредняяCVSS 5,3Proof of conceptEPSS 19 %

    connectwise · control23 янв. 2020 г.

  • CVE-2019-16515
    27Наблюдать

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    connectwise · control23 янв. 2020 г.