CVE-2020-15027: Critical severity connectwise vulnerability
ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15027?
CVE-2020-15027 is considered a medium severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2020-15027?
To mitigate CVE-2020-15027, upgrade ConnectWise Automate to version 2020.7 or apply the hotfix for version 2019.12.
What versions of ConnectWise Automate are affected by CVE-2020-15027?
CVE-2020-15027 affects ConnectWise Automate versions 2019.12 and versions between 2020.0 and 2020.6 inclusive.
What impact does CVE-2020-15027 have on authentication?
CVE-2020-15027 allows an attacker to bypass authentication through insufficient validation, compromising system access.
Was CVE-2020-15027 publicly disclosed?
Yes, CVE-2020-15027 was publicly disclosed as a vulnerability impacting ConnectWise Automate prior to its patch release.