CVE-2023-47257: Code Injection
Published Feb 1, 2024
·Updated
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
Affected Software
2 affected components
ConnectWise Automate
ConnectWise ScreenConnect<23.8.5
Event History
Feb 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-47257?
CVE-2023-47257 has a high severity level due to the potential for remote code execution by man-in-the-middle attackers.
2
How do I fix CVE-2023-47257?
To mitigate CVE-2023-47257, upgrade to the latest version of ConnectWise ScreenConnect that addresses this vulnerability.
3
What software versions are affected by CVE-2023-47257?
CVE-2023-47257 affects ConnectWise ScreenConnect versions up to 23.8.4 and ConnectWise Automate without specified versions.
4
What type of attack does CVE-2023-47257 enable?
CVE-2023-47257 allows man-in-the-middle attacks that can lead to remote code execution.
5
Is there a specific patch for CVE-2023-47257?
Yes, there is a patch included in the latest updates for ConnectWise ScreenConnect to fix CVE-2023-47257.