CVE-2021-32582: SQL Injection
An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrative credentials from an instance via crafted monitor status responses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32582?
CVE-2021-32582 is classified as a critical vulnerability due to its potential to allow SQL injection attacks.
How do I fix CVE-2021-32582?
To fix CVE-2021-32582, upgrade ConnectWise Automate to version 2021.5 or later.
What types of attacks are possible with CVE-2021-32582?
CVE-2021-32582 can allow attackers to perform blind SQL injection, leading to unauthorized access to database information.
Which versions of ConnectWise Automate are affected by CVE-2021-32582?
CVE-2021-32582 affects all versions of ConnectWise Automate prior to version 2021.5.
Can CVE-2021-32582 lead to data breaches?
Yes, CVE-2021-32582 can potentially lead to data breaches by exposing sensitive database information and administrative credentials.