First published: Thu Jan 23 2020(Updated: )
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ConnectWise | <=19.2.24707 | |
ConnectWise | =19.3.25270.7185 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-16516 is categorized as medium due to the potential for user enumeration by unauthorized attackers.
To fix CVE-2019-16516, update ConnectWise Control to version 19.3.25270.7186 or later.
CVE-2019-16516 affects users of ConnectWise Control versions up to 19.2.24707 and 19.3.25270.7185.
CVE-2019-16516 is a user enumeration vulnerability that allows attackers to verify the existence of usernames.
Yes, an unauthenticated attacker can exploit CVE-2019-16516 to determine if an account exists for a given username.