CVE-2019-16516: Medium severity connectwise vulnerability
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16516?
The severity of CVE-2019-16516 is categorized as medium due to the potential for user enumeration by unauthorized attackers.
How do I fix CVE-2019-16516?
To fix CVE-2019-16516, update ConnectWise Control to version 19.3.25270.7186 or later.
Who is affected by CVE-2019-16516?
CVE-2019-16516 affects users of ConnectWise Control versions up to 19.2.24707 and 19.3.25270.7185.
What type of vulnerability is CVE-2019-16516?
CVE-2019-16516 is a user enumeration vulnerability that allows attackers to verify the existence of usernames.
Can an unauthenticated attacker exploit CVE-2019-16516?
Yes, an unauthenticated attacker can exploit CVE-2019-16516 to determine if an account exists for a given username.