QID 150816

Date Published: 2024-02-29

QID 150816: ConnectWise ScreenConnect Multiple Vulnerabilities (CVE-2024-1708, CVE-2024-1709)

ConnectWise ScreenConnect is a Remote desktop and access software.

Multiple versions of ConnectWise ScreenConnect are affected by the following vulnerabilities:
CVE-2024-1708: A Path-traversal vulnerability that may allow an attacker to execute remote code or directly impact confidential data or critical systems.
CVE-2024-1709: An Authentication Bypass vulnerability using an Alternate Path or Channel, which may allow an attacker direct access to confidential information or critical systems.

Affected Versions:
ConnectWise ScreenConnect 23.9.7 and prior

QID Detection Logic (Unauthenticated):
This QID sends an HTTP GET request and checks the "Server" HTTP Response header to determine vulnerable version of ConnectWise ScreenConnect running on the target system.

Successful exploitation of these vulnerabilities could allow an attacker to execute remote code or directly impact confidential data or critical systems.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade ConnectWise ScreenConnect to version 23.9.8 or later to remediate this vulnerability. For more information please refer ConnectWise Security Bulletin

    CVEs related to QID 150816

    Software Advisories
    Advisory ID Software Component Link
    ConnectWise Security Bulletin URL Logo www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8