First published: Fri Oct 09 2020(Updated: )
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ConnectWise Automate | <2020.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15838 has a medium severity rating due to its potential for privilege escalation.
To fix CVE-2020-15838, you should update ConnectWise Automate to version 2020.8 or later and properly configure the permissions of the _LTUPDATE folder.
CVE-2020-15838 allows unauthorized users to escalate their privileges and gain access to sensitive functionalities within ConnectWise Automate.
CVE-2020-15838 affects all versions of ConnectWise Automate prior to 2020.8.
While the best course of action is to upgrade, a temporary workaround includes adjusting the permissions on the _LTUPDATE folder to prevent unauthorized access.